Executive brief
A security flaw exists in CAXperts UniversalPlantViewer WebServices Server, a platform used to manage digital twins and technical data for industrial plants. An authorized user with low-level permissions can intentionally deactivate the server's license, effectively shutting down the service for all users. This could lead to operational disruptions and loss of access to critical plant documentation and 3D models.
Technical details
An incorrect access control vulnerability exists within the '/api/License/deactivateOffline' endpoint of CAXperts UniversalPlantViewer WebServices Server version 2.7.6. The endpoint fails to properly validate that the requesting user has administrative privileges before processing license deactivation requests. A remote, authenticated attacker with low-level privileges can send a crafted request to this endpoint to remove the server's license. Successful exploitation results in a Denial of Service (DoS) condition as the webserver ceases to function without a valid license.
Affected products
- CAXperts UniversalPlantViewer WebServices Server 2.7.6
Timeline
- 2026-07-14: advisory: CVE published by NVD/MITRE