Account Escalation Vulnerability in Winter CMS by Winter
CVE-2026-27591
10CRITICAL
What is CVE-2026-27591?
Winter CMS, a free and open-source content management system, is susceptible to an account escalation vulnerability that allows authenticated backend users to modify their roles and permissions illegitimately. By sending specially crafted requests while logged into the backend, users can elevate their access level. To successfully exploit this vulnerability, an attacker must have some form of access to the backend with an existing user account. This flaw has been addressed in versions 1.0.477, 1.1.12, and 1.2.12.
Affected Version(s)
winter >= 1.2.0, < 1.2.12 < 1.2.0, 1.2.12
winter >= 1.1.0, < 1.1.12 < 1.1.0, 1.1.12
winter < 1.0.477 < 1.0.477
