CVE-2026-27198: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27198 is an improper privilege management vulnerability in Formwork, a flat file-based Content Management System (CMS). The flaw affects versions 2.0.0 through 2.3.3 and allows an authenticated user with the editor role to create new accounts with administrative privileges by bypassing role-based authorization checks during account creation. It was disclosed on February 18, 2026, by researcher G3XAR, with the GitHub Advisory Database publishing it on February 19, 2026, and NVD on February 21, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Formwork Advisory).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management). In the vulnerable UsersController.php, the create() method retrieves the requested role from form data and only validates that the role exists in the system — it does not check whether the currently authenticated user has sufficient privileges to assign that role. As a result, an editor-level user can submit a user-creation request specifying role=admin, and the application will accept and persist it without restriction. The patch in version 2.3.4 (commit 19390a0) corrects this by enforcing that non-admin users can only assign their own role to newly created accounts, and hides the role selection field from non-admin users in the UI (GitHub Advisory, Patch Commit).

Impact

Successful exploitation grants an attacker full administrative control over the Formwork CMS, enabling them to access all site data and user information, modify system configuration and security settings, and create, modify, or delete any user account including legitimate administrators. Because the attack requires only a low-privileged editor account and no user interaction, the barrier to full CMS compromise is minimal. There is no direct operating system-level code execution, but complete CMS takeover can facilitate content defacement, credential harvesting, and further attacks against site visitors (GitHub Advisory, Formwork Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain editor credentials: Acquire valid editor-level credentials for the target Formwork CMS instance, either through phishing, credential stuffing, or social engineering.
  2. Authenticate to the panel: Log in to the Formwork admin panel (typically at /panel/) using the editor account.
  3. Navigate to user creation: Access the user management section of the panel where editors are permitted to create new users.
  4. Intercept and modify the request: Using a proxy tool such as Burp Suite, intercept the HTTP POST request submitted when creating a new user.
  5. Inject privileged role: Modify the role parameter in the POST body from editor (or the default) to admin, then forward the request to the server.
  6. Verify privilege escalation: Log in with the newly created account and confirm full administrative access to the CMS, including access to all configuration, user management, and site data (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: CMS access logs showing POST requests to the user creation endpoint (e.g., /panel/users/create) from editor-role sessions with a role=admin parameter value; unexpected new admin accounts appearing in user management logs shortly after editor login events.
  • File System: New or unexpected flat-file user records in the Formwork data directory (e.g., site/accounts/) with role: admin assigned to accounts not created by a legitimate administrator.
  • Application Behavior: Presence of admin-role accounts whose creation timestamp does not correspond to any known administrative activity; editor accounts that subsequently perform administrative actions such as modifying system configuration or deleting other users.

Mitigation and workarounds

The vendor has released Formwork version 2.3.4, which fixes this vulnerability by ensuring non-admin users can only assign their own role during account creation and by hiding the role selection UI element from non-admin users. All installations running versions 2.0.0 through 2.3.3 should upgrade to 2.3.4 immediately. As an interim measure, restrict editor role assignments to fully trusted users and audit all existing user accounts for unauthorized administrative accounts created after deploying an affected version (GitHub Release, Patch Commit).

Community reactions

The vulnerability received limited but notable coverage from security aggregators and community outlets. The Hacker Wire published a dedicated write-up on the authorization bypass (The Hacker Wire), and the issue was discussed on Bluesky by security community accounts. Coverage was also picked up by vulnerability tracking platforms including VulnDB, CVEFeed, and Vulners. Overall community sentiment reflects the straightforward nature of the flaw and the availability of a patch, with no significant controversy or widespread alarm.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management