Access Control Issue in Vvveb CMS by Givanz
CVE-2026-49221
What is CVE-2026-49221?
Vvveb, a content management system developed by Givanz, has a significant vulnerability in its backend digital asset management. Before version 1.0.8.4, low-privileged users could exploit inadequate enforcement of ownership boundaries associated with digital assets. This weakness allows unauthorized access to critical operations, where an attacker could exploit the admin/controller/product/digital-asset.php and admin/sql/sqlite/digital_asset.sql components. Potential consequences include unauthorized listing and reading of asset names, alteration of asset metadata, and even deletion of vital asset records. The resultant data exposure can lead to the disclosure of sensitive product metadata and pose a risk of resource link corruption and data loss. Users are advised to upgrade to version 1.0.8.4 to mitigate these risks.
Affected Version(s)
Vvveb < 1.0.8.4
