Arbitrary File Access and Deletion in Vvveb CMS by Givanz
CVE-2026-55231

7.2HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-55231?

Vvveb, a user-friendly content management system with an integrated page builder, is susceptible to a significant vulnerability that impacts users with higher access privileges. Before the release of version 1.0.8.6, the CMS featured an inadequate central path sanitization mechanism. This flaw allowed authenticated admin-panel users, particularly those with backup access, to read and delete arbitrary files on the server. Potential ramifications include unauthorized access to sensitive information such as database credentials stored in the config/db.php file, examination of critical system files like /etc/passwd, and the capability to delete essential configuration files, leading to a complete takeover by forcing the site into installation mode. Users are strongly encouraged to upgrade to the patched version to mitigate these risks.

Affected Version(s)

Vvveb < 1.0.8.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.