Junglewise Threat Intelligence

CVE-2026-35552: CAXperts UPVWebServices and UDiTH Portal Improper Access Control

CVE-2026-35552 · Severity: info · CVSS 6.5 · Published 2026-07-08

Executive brief

CAXperts UPVWebServices and UDiTH Portal, which are used to manage industrial 'digital twin' data for large-scale plants, contain a security flaw that allows any logged-in user to perform administrative actions. Specifically, a non-privileged user can remotely deactivate the application's license. This would result in a total service outage, preventing all employees from accessing critical plant documentation, 3D models, and real-time monitoring data until an administrator manually restores the system.

Technical details

An improper access control vulnerability (CWE-284) exists in the administrative API of CAXperts UPVWebServices and UDiTH Portal. The root cause is a missing authorization check on a specific endpoint responsible for license management. A remote attacker with low-privileged, authenticated access can send a crafted request to this endpoint to deactivate the application's license. This action results in a complete denial of service (DoS) for all users. The vulnerability is resolved in UPVWebServices version 2.7.7 and UDiTH Portal version 2026.2.1.

Affected products

  • CAXperts UPVWebServices 2.4.2212.603 through 2.7.6
  • CAXperts UDiTH Portal 2026.0.0 through 2026.2.0

Timeline

  • 2026-07-01: disclosed: Internal advisory date
  • 2026-07-08: advisory: NVD publication date
  • 2026-07-08: patched: Fixed versions identified in advisory

References