Security Advisory

CVE-2026-14952

7.5
HIGH

Vulnerability Description

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Published Date August 20, 2026
Official Source NIST NVD Advisory