CVE-2026-23754 | D-Link D-View 8 up to 2.0.1.107 API Endpoint user_id authorization (EUVD-2026-3605)
A vulnerability classified as very critical has been found in D-Link D-View 8 up to 2.0.1.107. Affected is an unknown function of the component API Endpoint. This manipulation of the argument user_id causes authorization bypass.
This vulnerability is tracked as CVE-2026-23754. The attack is possible to be carried out remotely. No exploit exists.