
CVE-2026-14949 A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts… https://www.cve.org/CVERecord?id=CVE-2026-14949
Post summary
CVE-2026-14949 allows a remote attacker who has a valid session to create arbitrary user accounts via the /api/user/add.php endpoint.

