CVE-2026-35552

HIGH

CAXperts UPVWebServices 2.4.2212.603-2.7.6 & UDiTH Portal 2026.0.0-2026.2.0 Authenticated License Deactivation via API

Title source: llm
STIX 2.1

Description

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.

Scores

CVSS v3 8.1
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Published Jul 08, 2026
Tracked Since Jul 09, 2026