{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-14952/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14950"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FDS 102 (2.1.0 to 2.13.3)","FDS 102 (2.8.0-2.13.3)","FDS 102","FDS 102 (2.13.0 - 2.13.3)"],"_cs_severities":["critical"],"_cs_tags":["cve","vulnerability","rce","industrial-control-system","path-traversal","cve-2026-14948","session-hijacking","information-disclosure","cwe-532","cve-2026-14952","industrial-control-systems","rails"],"_cs_type":"advisory","_cs_vendors":["Frauscher Sensortechnik"],"content_html":"\u003cp\u003eCVE-2026-14950 identifies an insufficient session expiration flaw (CWE-613) within the web interface of the Frauscher Sensortechnik FDS 102 system, affecting versions 2.1.0 through 2.13.3. This vulnerability enables an unauthenticated attacker who has obtained a valid session identifier - potentially through interception, theft, or by leveraging an unattended machine - to continue using the session indefinitely, even after the system's expiration policy should have terminated it. This persistence mechanism allows unauthorized users to maintain an active, authenticated state, effectively bypassing standard session timeout security controls. Defenders should prioritize patching affected FDS 102 units and implement strict monitoring for anomalous session activity or unauthorized session token reuse.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 score of 9.8 (Critical), indicating high risk for unauthorized access and control over the affected FDS 102 interface. If exploited, an attacker gains persistent access to the management environment, potentially leading to unauthorized monitoring or configuration changes of sensitive industrial sensor systems. The vulnerability affects a critical component of industrial infrastructure management, and failure to apply available patches leaves systems open to prolonged unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security update provided by Frauscher Sensortechnik to all FDS 102 instances running version 2.13.3 or earlier to remediate CVE-2026-14950.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for session tokens that persist beyond expected operational windows or show abnormal temporal patterns.\u003c/li\u003e\n\u003cli\u003eEnforce strict session management policies, including idle timeouts and secure transport (HTTPS) to mitigate the risk of session identifier interception.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T11:12:29Z","date_published":"2026-08-20T11:11:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fds-session-expiration/","summary":"CVE-2026-14950 is an insufficient session expiration vulnerability in Frauscher Sensortechnik FDS 102 that allows an attacker with a valid session identifier to maintain access beyond the intended expiration time.","title":"Insufficient Session Expiration in Frauscher Sensortechnik FDS 102","url":"https://feed.craftedsignal.io/briefs/2026-08-fds-session-expiration/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-14952","version":"https://jsonfeed.org/version/1.1"}