Security Advisory
CVE-2026-14953
4.3
MEDIUM
Vulnerability Description
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.
Published Date
August 20, 2026
Official Source
NIST NVD Advisory