CVE-2026-34427

Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super Administrator privileges, enabling plugin upload functionality for remote code execution.
Configurations

No configuration.

History

20 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 16:16

Updated : 2026-07-14 19:17


NVD link : CVE-2026-34427

Mitre link : CVE-2026-34427

CVE.ORG link : CVE-2026-34427


JSON object : View

Products Affected

No product.

CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes