CAXperts Universal Plant Viewer WebServices Server Broken Access Control Vulnerability Allowing Denial-of-Service

Vulnerability

A broken access control vulnerability has been identified in CAXperts Universal Plant Viewer WebServices Server version 2.7.6. This vulnerability allows authenticated attackers with low-level privileges to cause a denial-of-service by deactivating the application license on the web server. The issue arises because the '/api/License/deactivateOffline' endpoint lacks proper authorization checks, enabling unauthorized license deactivation.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing a loss of availability for all users of the application.

Reproduction

The vulnerability can be reproduced by an authenticated user with low-level privileges. After logging in, the user can access the '/api/License/deactivateOffline' endpoint, which will deactivate the application license without any authorization checks. This action removes the license from the server, causing a denial-of-service for all users.

Remediation

CAXperts has released a patch for this vulnerability in version 2026.3.0, which improves license handling. Users are advised to update to this version.

Added: Jul 15, 2026, 3:32 AM
Updated: Jul 15, 2026, 3:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.