CVE-2026-27591 is a critical access escalation vulnerability affecting Winter CMS versions prior to 1.0.477, 1.1.12, and 1.2.12. It allows an authenticated backend user to escalate their privileges by modifying assigned roles and permissions through specially crafted requests. Rated 9.9 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), this vulnerability has low attack complexity and requires only low privileges, enabling a network-based attacker to achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.477CPE matchmatch criteria | cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.12CPE matchmatch criteria | cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:* | ||
>= 1.2.0, < 1.2.12CPE matchmatch criteria | cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.