What is CVE-2026-49228?
CVE-2026-49228 is a vulnerability in Vvveb CMS versions prior to 1.0.8.4, where low-privileged Vendor users can access products belonging to other Vendors via backend product operations. The issue stems from the `admin/controller/product/products.php` controller, which can be exploited for unauthorized access. Users are advised to upgrade to version 1.0.8.4 immediately.
Azərbaycanca: CVE-2026-49228 Vvveb CMS-in 1.0.8.4-dən əvvəlki versiyalarında aşağı səlahiyyətli Vendor istifadəçilərinə başqa Vendor-a məxsus məhsullara giriş imkanı verən zəiflikdir. Təsirə məruz qalan sistemlərdə hücumçu `admin/controller/product/products.php` kontrolleri vasitəsilə icazəsiz əməliyyatlar apara bilər. İstifadəçilərə ən qısa zamanda 1.0.8.4 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Vvveb CMS are affected by CVE-2026-49228?
This vulnerability affects Vvveb CMS versions prior to 1.0.8.4.
What is the recommended mitigation for CVE-2026-49228?
Users are advised to upgrade to Vvveb CMS version 1.0.8.4 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.