CVE-2018-12596 is a critical improper access restriction vulnerability affecting Episerver Ektron CMS versions prior to 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, and 9.2 before SP2 Site CU 22. This flaw allows unauthenticated remote attackers to bypass access controls and execute aspx pages, including those typically restricted to local administrators within the /WorkArea/ path, via the "activateuser.aspx" page. With a CVSSv3 score of 9.8 (CRITICAL), this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability of the affected system without requiring user interaction or authentication. The EPSS score of 0.479190000 indicates a higher-than-average probability of exploitation compared to other CVEs. While not listed in CISA's KEV catalog, an exploit (EDB-45577) is publicly available on ExploitDB, confirming the feasibility of exploitation. Despite the critical severity and public exploit, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.00CPE matchmatch criteria | cpe:2.3:a:episerver:ektron_cms:9.00:-:*:*:*:*:*:* | ||
9.00CPE matchmatch criteria | cpe:2.3:a:episerver:ektron_cms:9.00:sp1:*:*:*:*:*:* | ||
9.00CPE matchmatch criteria | cpe:2.3:a:episerver:ektron_cms:9.00:sp2:*:*:*:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:a:episerver:ektron_cms:9.10:-:*:*:*:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:a:episerver:ektron_cms:9.10:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.