Account Escalation Vulnerability in Winter CMS by Winter
CVE-2026-27591

10CRITICAL

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-27591?

Winter CMS, a free and open-source content management system, is susceptible to an account escalation vulnerability that allows authenticated backend users to modify their roles and permissions illegitimately. By sending specially crafted requests while logged into the backend, users can elevate their access level. To successfully exploit this vulnerability, an attacker must have some form of access to the backend with an existing user account. This flaw has been addressed in versions 1.0.477, 1.1.12, and 1.2.12.

Affected Version(s)

winter >= 1.2.0, < 1.2.12 < 1.2.0, 1.2.12

winter >= 1.1.0, < 1.1.12 < 1.1.0, 1.1.12

winter < 1.0.477 < 1.0.477

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.