Ad

CVE-2026-27591

CRITICAL CVSS 3.1: 9.9 EPSS 0.09%
Updated Mar 19, 2026
Wintercms
Parameter Value
CVSS 9.9 (CRITICAL)
Affected Versions 1.1.0 — 1.2.12
Fixed In 1.0.477
Type CWE-639 (Authorization Bypass), CWE-284 (Improper Access Control), CWE-915
Vendor Wintercms
Public PoC No

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access.

This vulnerability is fixed in 1.0.477, 1.1.12, and 1.2.12.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Wintercms Winter
cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:*
1.0.477
Wintercms Winter
cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:*
1.1.0 1.1.12
Wintercms Winter
cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:*
1.2.0 1.2.12