Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control on License Deactivation Endpoint Causes Denial of Service

Fri, 17 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via License Deactivation in UniversalPlantViewer WebServices Server

Thu, 16 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via License Deactivation in UniversalPlantViewer WebServices Server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-15T14:12:29.134Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36035

cve-icon Vulnrichment

Updated: 2026-07-15T14:12:19.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T10:15:02Z

Weaknesses