What is CVE-2026-49222?
CVE-2026-49222 is a vulnerability in Vvveb CMS prior to version 1.0.8.4 that allows a low-privileged Vendor to manage questions belonging to another Vendor's products due to missing authorization checks in `product_question.sql` queries. An immediate update to the latest version is recommended for affected systems.
Azərbaycanca: CVE-2026-49222, Vvveb CMS-in 1.0.8.4 versiyasından əvvəlki versiyalarında aşağı imtiyazlı Vendor istifadəçisinə başqa Vendor-un məhsullarına aid sualları idarə etməyə imkan verən zəiflikdir. Bu, `product_question.sql` sorğularında səlahiyyət yoxlamasının olmaması səbəbindən baş verir. Təsirə məruz qalan sistemlərdə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Vvveb CMS are affected by CVE-2026-49222 and what is the cause of the vulnerability?
The vulnerability affects Vvveb CMS versions prior to 1.0.8.4. It is caused by missing authorization checks in `product_question.sql` queries.
What can a low-privileged user do by exploiting CVE-2026-49222?
A low-privileged Vendor can manage questions belonging to another Vendor's products.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.