Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48365

24
FAUCET Score

CVE-2022-48365 describes an excessive privileges vulnerability in eZ Platform Ibexa Kernel before version 1.3.26, where the "Company admin" role grants more access than intended. This high-severity vulnerability (CVSS 7.2) is network-exploitable with low complexity, requiring high privileges, and could lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.3.0, < 3.3.28CPE matchmatch criteria
cpe:2.3:a:ibexa:digital_experience_platform:*:*:*:*:*:*:*:*
>= 4.2.0, < 4.2.3CPE matchmatch criteria
cpe:2.3:a:ibexa:digital_experience_platform:*:*:*:*:*:*:*:*
>= 2.5.0, < 2.5.31CPE matchmatch criteria
cpe:2.3:a:ibexa:ez_platform:*:*:*:*:*:*:*:*
>= 1.3.0, < 1.3.26CPE matchmatch criteria
cpe:2.3:o:ibexa:ez_platform_kernel:*:*:*:*:*:*:*:*
>= 7.5.0, < 7.5.30CPE matchmatch criteria
cpe:2.3:o:ibexa:ez_platform_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.86%
Probability of exploitation in next 30 days
EPSS Percentile
54.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0086 is in the 37th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: ezsystems/ezpublish-kernelFixed in: 7.5.30
composerpatch availablevia ghsa
Product: ezsystems/ezplatform-kernelFixed in: 1.3.26
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-qq2j-9pf8-g58chigh

Company admin role gives excessive privileges in eZ Platform Ibexa

Mar 12, 2023

References

developers.ibexa.co / security-advisories/ibexa-sa-2022-009-critical-vulnerabilities-in-graphql-role-assignment-ct-editing-and-drafts-tooltips
Vendor Advisory
github.com / ezsystems/ezplatform-kernel/security/advisories/GHSA-8h83-chh2-fchp
Vendor Advisory
github.com / ezsystems/ezpublish-kernel/commit/957e67a08af2b3265753f9763943e8225ed779ab
Patch
github.com / ezsystems/ezpublish-kernel/security/advisories/GHSA-99r3-xmmq-7q7g
Vendor Advisory