LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-14950

Published
CVSS9.8
Severitycritical
WeaknessCWE-613
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-14950

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-14950.