Privilege Escalation Vulnerability in CouchCMS by CouchCMS
CVE-2026-29002
Key Information:
Badges
What is CVE-2026-29002?
CouchCMS suffers from a privilege escalation flaw that permits authenticated Admin-level users to create SuperAdmin accounts. This vulnerability arises from improper validation of the f_k_levels_list parameter during user creation requests. By manipulating the parameter value from 4 to 10 in the HTTP request, attackers can circumvent the authorization checks, granting them full control over the application, and bypassing the restrictions on SuperAdmin privilege assignments.
Affected Version(s)
CouchCMS 0 <= 2.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
