Role-Based Authorization Flaw in Formwork CMS by Getformwork
CVE-2026-27198
8.8HIGH
What is CVE-2026-27198?
An access control vulnerability exists in Formwork CMS (versions 2.0.0 to 2.3.3) where role-based authorization is not properly enforced during account creation. Although the application checks whether the specified role exists, it fails to ensure that the user has adequate permissions to assign high-level roles, such as admin. This oversight allows authenticated users with lower privileges (specifically editors) to create new accounts with administrative access, potentially compromising the entire CMS. This vulnerability has been rectified in Formwork version 2.3.4.
Affected Version(s)
formwork >= 2.0.0, < 2.3.4
