CVE-2026-14950
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.60%
- CWE
- CWE-613
- Published
- 2026-08-20
- Last modified
- 2026-08-20
Affected products
- Frauscher Sensortechnik FDS 102
Weakness type
Related vulnerabilities
- CVE-2026-87014 — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
- CVE-2026-80174 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2026-86215 — Mstfakts College-Management-System Logout server.php session expiration
- CVE-2026-55513 — nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
- CVE-2026-61608 — SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links
- CVE-2026-84480 — WWBN AVideo Password Recovery Token Expiration Bypass
- CVE-2026-84203 — Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change