Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:couchcms:couchcms:*:*:*:*:*:*:*:* |
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Couchcms
Couchcms couchcms |
|
| Vendors & Products |
Couchcms
Couchcms couchcms |
Fri, 10 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorization validation and gain full application control, circumventing restrictions on SuperAdmin account creation and privilege assignment. | |
| Title | CouchCMS Privilege Escalation via f_k_levels_list Parameter | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-10T16:20:02.847Z
Reserved: 2026-03-03T16:42:01.012Z
Link: CVE-2026-29002
Updated: 2026-04-10T16:19:57.206Z
Status : Analyzed
Published: 2026-04-10T16:16:30.513
Modified: 2026-04-16T19:41:17.740
Link: CVE-2026-29002
No data.
OpenCVE Enrichment
Updated: 2026-04-13T13:01:22Z