CVE-2026-36035 Details
Description
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
A broken access control vulnerability has been identified in CAXperts Universal Plant Viewer WebServices Server version 2.7.6. This vulnerability allows authenticated attackers with low-level privileges to cause a denial-of-service by deactivating the application license on the web server. The issue arises because the '/api/License/deactivateOffline' endpoint lacks proper authorization checks, enabling unauthorized license deactivation.
CAXperts has released a patch for this vulnerability in version 2026.3.0, which improves license handling. Users are advised to update to this version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://caxperts.com | [email protected] | Vendor |
| https://medium.com/@hacker.dan/hello-world-first-post-first-cve-6671b82e2b71 | [email protected] | ExploitTechnical Description |
| https://universalplantviewer.com | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| CAXperts UniversalPlantViewer | < 2026.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion