CVE-2026-12593
Qt Axivion
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the tok...
- CVSS
- 8.7
- EPSS
- 0.28% 20.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09