Role-Based Authorization Flaw in Formwork CMS by Getformwork
CVE-2026-27198

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 February 2026

What is CVE-2026-27198?

An access control vulnerability exists in Formwork CMS (versions 2.0.0 to 2.3.3) where role-based authorization is not properly enforced during account creation. Although the application checks whether the specified role exists, it fails to ensure that the user has adequate permissions to assign high-level roles, such as admin. This oversight allows authenticated users with lower privileges (specifically editors) to create new accounts with administrative access, potentially compromising the entire CMS. This vulnerability has been rectified in Formwork version 2.3.4.

Affected Version(s)

formwork >= 2.0.0, < 2.3.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.