User Access Flaw in Vvveb CMS Allows Unauthorized Content Manipulation
CVE-2026-49224

8.3HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-49224?

The Vvveb CMS has a vulnerability that allows low-privileged users to access and manipulate post revisions owned by other authors. Specifically, before version 1.0.8.4, the backend post revision functionalities did not correctly enforce access control on revision operations. As a result, an attacker with limited privileges could potentially read historic content, restore revisions over a different author's live posts, or delete revision records. This could lead to unauthorized exposure of sensitive drafts, corruption of published content, and significant disruption of the audit trail. The security flaw has been rectified in version 1.0.8.4.

Affected Version(s)

Vvveb < 1.0.8.4

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.