Loading market data...
← Back to CVE feed

CVE-2026-35063

UNKNOWN View on NVD ↗

Description

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access.

Published: Apr 09, 2026 20:16 UTC Modified: Apr 09, 2026 20:16 UTC