What is CVE-2026-49224?
CVE-2026-49224 is a vulnerability in Vvveb CMS before version 1.0.8.4 that allows a low-privileged Author to access post revisions belonging to another Author due to a flaw in the `admin/controller/content/revisions.php` controller. Users should immediately update to version 1.0.8.4 or later.
Azərbaycanca: CVE-2026-49224, Vvveb CMS-in 1.0.8.4 versiyasından əvvəlki versiyalarında aşağı səlahiyyətli "Author" istifadəçilərinə, başqa bir "Author"a məxsus yazı reviziyalarına giriş imkanı verən zəiflikdir. Bu, `admin/controller/content/revisions.php` nəzarətçisindəki qüsurdan qaynaqlanır. Vvveb istifadəçiləri dərhal 1.0.8.4 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which user role is affected by CVE-2026-49224 in Vvveb CMS?
This vulnerability affects low-privileged 'Author' users.
Which file in Vvveb CMS is the cause of the CVE-2026-49224 vulnerability?
The vulnerability stems from a flaw in the `admin/controller/content/revisions.php` controller.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.