
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27198 is an improper privilege management vulnerability in Formwork, a flat file-based Content Management System (CMS). The flaw affects versions 2.0.0 through 2.3.3 and allows an authenticated user with the editor role to create new accounts with administrative privileges by bypassing role-based authorization checks during account creation. It was disclosed on February 18, 2026, by researcher G3XAR, with the GitHub Advisory Database publishing it on February 19, 2026, and NVD on February 21, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Formwork Advisory).
The root cause is classified as CWE-269 (Improper Privilege Management). In the vulnerable UsersController.php, the create() method retrieves the requested role from form data and only validates that the role exists in the system — it does not check whether the currently authenticated user has sufficient privileges to assign that role. As a result, an editor-level user can submit a user-creation request specifying role=admin, and the application will accept and persist it without restriction. The patch in version 2.3.4 (commit 19390a0) corrects this by enforcing that non-admin users can only assign their own role to newly created accounts, and hides the role selection field from non-admin users in the UI (GitHub Advisory, Patch Commit).
Successful exploitation grants an attacker full administrative control over the Formwork CMS, enabling them to access all site data and user information, modify system configuration and security settings, and create, modify, or delete any user account including legitimate administrators. Because the attack requires only a low-privileged editor account and no user interaction, the barrier to full CMS compromise is minimal. There is no direct operating system-level code execution, but complete CMS takeover can facilitate content defacement, credential harvesting, and further attacks against site visitors (GitHub Advisory, Formwork Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/panel/) using the editor account.role parameter in the POST body from editor (or the default) to admin, then forward the request to the server./panel/users/create) from editor-role sessions with a role=admin parameter value; unexpected new admin accounts appearing in user management logs shortly after editor login events.site/accounts/) with role: admin assigned to accounts not created by a legitimate administrator.The vendor has released Formwork version 2.3.4, which fixes this vulnerability by ensuring non-admin users can only assign their own role during account creation and by hiding the role selection UI element from non-admin users. All installations running versions 2.0.0 through 2.3.3 should upgrade to 2.3.4 immediately. As an interim measure, restrict editor role assignments to fully trusted users and audit all existing user accounts for unauthorized administrative accounts created after deploying an affected version (GitHub Release, Patch Commit).
The vulnerability received limited but notable coverage from security aggregators and community outlets. The Hacker Wire published a dedicated write-up on the authorization bypass (The Hacker Wire), and the issue was discussed on Bluesky by security community accounts. Coverage was also picked up by vulnerability tracking platforms including VulnDB, CVEFeed, and Vulners. Overall community sentiment reflects the straightforward nature of the flaw and the availability of a patch, with no significant controversy or widespread alarm.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."