High severity7.2NVD Advisory· Published Apr 10, 2026· Updated Apr 16, 2026
CVE-2026-29002
CVE-2026-29002
Description
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorization validation and gain full application control, circumventing restrictions on SuperAdmin account creation and privilege assignment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- gist.github.com/thepiyushkumarshukla/477e2d2bbbe8cc3ec0d640c50f0cf9e1nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/couchcms-privilege-escalation-via-f-k-levels-list-parameternvdThird Party Advisory
- www.couchcms.comnvdProduct
News mentions
0No linked articles in our index yet.