Access Control Issue in Vvveb CMS by Givanz
CVE-2026-49221

8.8HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-49221?

Vvveb, a content management system developed by Givanz, has a significant vulnerability in its backend digital asset management. Before version 1.0.8.4, low-privileged users could exploit inadequate enforcement of ownership boundaries associated with digital assets. This weakness allows unauthorized access to critical operations, where an attacker could exploit the admin/controller/product/digital-asset.php and admin/sql/sqlite/digital_asset.sql components. Potential consequences include unauthorized listing and reading of asset names, alteration of asset metadata, and even deletion of vital asset records. The resultant data exposure can lead to the disclosure of sensitive product metadata and pose a risk of resource link corruption and data loss. Users are advised to upgrade to version 1.0.8.4 to mitigate these risks.

Affected Version(s)

Vvveb < 1.0.8.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.