Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to assign highly privileged roles such as admin. As a result, an authenticated user with the editor role can create a new account with administrative privileges, leading to full administrative access and complete compromise of the CMS. This issue has been fixed in version 2.3.4.
History

Tue, 03 Mar 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Formwork Project
Formwork Project formwork
CPEs cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:*
Vendors & Products Formwork Project
Formwork Project formwork

Wed, 25 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Getformwork
Getformwork formwork
Vendors & Products Getformwork
Getformwork formwork

Sat, 21 Feb 2026 05:30:00 +0000

Type Values Removed Values Added
Description Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to assign highly privileged roles such as admin. As a result, an authenticated user with the editor role can create a new account with administrative privileges, leading to full administrative access and complete compromise of the CMS. This issue has been fixed in version 2.3.4.
Title Formwork Improperly Manages Privileges During User Creation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-21T05:11:42.535Z

Updated: 2026-02-24T19:01:22.284Z

Reserved: 2026-02-18T19:47:02.155Z

Link: CVE-2026-27198

cve-icon Vulnrichment

Updated: 2026-02-24T19:01:15.608Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-21T06:17:00.543

Modified: 2026-03-03T17:33:54.540

Link: CVE-2026-27198

cve-icon Redhat

No data.