CVE-2024-46310

Critical severity, CVSS 9.1. EPSS: 2.5% chance of exploitation in the next 30 days.

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

Published 2025-01-13. Last modified 2026-07-05.