CAXperts UniversalPlantViewer
- < 2026.3.0
A broken access control vulnerability has been identified in CAXperts Universal Plant Viewer WebServices Server version 2.7.6. This vulnerability allows authenticated attackers with low-level privileges to cause a denial-of-service by deactivating the application license on the web server. The issue arises because the '/api/License/deactivateOffline' endpoint lacks proper authorization checks, enabling unauthorized license deactivation.
Exploitation of this vulnerability leads to a denial-of-service condition, causing a loss of availability for all users of the application.
The vulnerability can be reproduced by an authenticated user with low-level privileges. After logging in, the user can access the '/api/License/deactivateOffline' endpoint, which will deactivate the application license without any authorization checks. This action removes the license from the server, causing a denial-of-service for all users.
CAXperts has released a patch for this vulnerability in version 2026.3.0, which improves license handling. Users are advised to update to this version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.