Home
HIGH: 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
3.0.0.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.0.0.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.0.0.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.0.0.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.0.0.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
3.0.0.0 (semver) before 4.21.0.0
affected
Description
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
Problem types
CWE-863 Incorrect Authorization
Product status
3.0.0.0 (semver) before 3.5.22.20
3.0.0.0 (semver) before 3.5.22.20
3.0.0.0 (semver) before 3.5.22.20
3.0.0.0 (semver) before 3.5.22.20
3.0.0.0 (semver) before 3.5.22.20
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
3.0.0.0 (semver) before 4.21.0.0
Credits
ABB AG
References
www.certvde.com/en/advisories/VDE-2026-056/