Status: UPDATED
| Advisory ID: CVE-2026-14168
Key Details
| CVE | CVE-2026-14168 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-07-30 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-862 (Missing Authorization) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
What to Do
Monitor ads-tec Industrial IT's web page for any future patch releases.
References