
CVE-2026-14953 A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php. https://www.cve.org/CVERecord?id=CVE-2026-14953
Post summary
CVE-2026-14953 exposes an API endpoint that lets low‑privileged remote attackers enumerate all users and determine which ones have elevated privileges, without any known PoC, exploit code, or active exploitation reports.
