CVE Vulnerabilities

CVE-2020-26167

Published: Nov 04, 2020 | Modified: May 30, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.

Affected Software

NameVendorStart VersionEnd Version
Fuel_cmsThedaylightstudio*1.4.12 (including)

References