Security Advisory
CVE-2026-14952
7.5
HIGH
Vulnerability Description
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Published Date
August 20, 2026
Official Source
NIST NVD Advisory