CVE-2026-14953
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Aug 20, 2026
Vendor
unknown
Description
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.