CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorization validation and gain full application control, circumventing restrictions on SuperAdmin account creation and privilege assignment.
References
| Link | Resource |
|---|---|
| https://gist.github.com/thepiyushkumarshukla/477e2d2bbbe8cc3ec0d640c50f0cf9e1 | Exploit Third Party Advisory |
| https://www.couchcms.com/ | Product |
| https://www.vulncheck.com/advisories/couchcms-privilege-escalation-via-f-k-levels-list-parameter | Third Party Advisory |
Configurations
History
16 Apr 2026, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:couchcms:couchcms:*:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/thepiyushkumarshukla/477e2d2bbbe8cc3ec0d640c50f0cf9e1 - Exploit, Third Party Advisory | |
| References | () https://www.couchcms.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/couchcms-privilege-escalation-via-f-k-levels-list-parameter - Third Party Advisory | |
| First Time |
Couchcms
Couchcms couchcms |
10 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 16:16
Updated : 2026-04-16 19:41
NVD link : CVE-2026-29002
Mitre link : CVE-2026-29002
CVE.ORG link : CVE-2026-29002
JSON object : View
Products Affected
couchcms
- couchcms
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
