CVE-2026-95263
Received Received - Intake

Incorrect Access Control in Feehi CMS 2.1.1

Vulnerability report for CVE-2026-95263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Feehi CMS 2.1.1 has an Incorrect Access Control vulnerability. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account without providing the old password. This happens because the server does not enforce protection for the super administrator account during updates.

Detection Guidance

To detect this vulnerability, check if Feehi CMS version 2.1.1 is installed. Inspect the backend files for AdminUserController.php, AdminUserService.php, and AdminUser.php. Monitor POST requests to the admin-user/update endpoint for unauthorized password changes to the super administrator account.

Impact Analysis

An authenticated attacker could exploit this to escalate privileges remotely. They could take full control of the CMS by changing the super administrator password, gaining access to all administrative functions and potentially sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update Feehi CMS to a patched version if available. Restrict access to the admin-user/update endpoint and enforce old password verification. Remove unnecessary administrator-update permissions for low-privilege accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95263. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart