CVE-2026-27591 - Vulnerability Analysis
CriticalCVSS: 9.9Last Updated: March 12, 2026
Winter CMS - Broken Access Control
Overview
Winter CMS < 1.0.477, < 1.1.12, and < 1.2.12 contains a broken access control vulnerability caused by improper validation of role and permission modifications, letting authenticated backend users escalate privileges, exploit requires authenticated backend access.
Severity & Score
Impact
Authenticated backend users can escalate their privileges, potentially gaining full administrative control.
Mitigation
Upgrade to versions 1.0.477, 1.1.12, or 1.2.12 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-27591 - Critical (9.9) Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modi... š https://www.thehackerwire.com/vulnerability/CVE-2026-27591/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27591
- Severity
- Critical
- CVSS Score
- 9.9
- Type
- broken_access_control
- Status
- unconfirmed
- EPSS
- 6.1%
- Social Posts
- 1
CWE
- CWE-284
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H