CVE Watchtower


← Back to CVE List

CVE-2026-27591NVD

Vulnerability Summary

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access. This vulnerability is fixed in 1.0.477, 1.1.12, and 1.2.12.
Severity Level
CRITICAL(9.9)
Published Date
Mar 11, 2026
Last Modified
Mar 12, 2026
Exploitation Status
UNKNOWN
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
EPSS Score (30-Day)
0.08%Probability
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh