User Access Flaw in Vvveb CMS Allows Unauthorized Content Manipulation
CVE-2026-49224
8.3HIGH
What is CVE-2026-49224?
The Vvveb CMS has a vulnerability that allows low-privileged users to access and manipulate post revisions owned by other authors. Specifically, before version 1.0.8.4, the backend post revision functionalities did not correctly enforce access control on revision operations. As a result, an attacker with limited privileges could potentially read historic content, restore revisions over a different author's live posts, or delete revision records. This could lead to unauthorized exposure of sensitive drafts, corruption of published content, and significant disruption of the audit trail. The security flaw has been rectified in version 1.0.8.4.
Affected Version(s)
Vvveb < 1.0.8.4
