PT-2026-21344 · Formwork · Formwork

G3Xar

·

Published

2026-02-19

·

Updated

2026-03-23

·

CVE-2026-27198

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Formwork versions 2.0.0 through 2.3.3
Description Formwork is a flat file-based Content Management System (CMS). The application does not properly enforce role-based authorization during account creation. Specifically, it does not verify if the current user has the necessary privileges to assign highly privileged roles, such as admin. This allows an authenticated user with the editor role to create a new account with administrative privileges, resulting in full administrative access and potential compromise of the CMS.
Recommendations Update to version 2.3.4 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27198
GHSA-34P4-7W83-35G2

Affected Products

Formwork