CVE-2026-35552
HIGHCAXperts UPVWebServices 2.4.2212.603-2.7.6 & UDiTH Portal 2026.0.0-2026.2.0 Authenticated License Deactivation via API
Title source: llmDescription
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
References (2)
Core 2
Scores
CVSS v3
8.1
EPSS
0.0028
EPSS Percentile
19.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026