Description
Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to assign highly privileged roles such as admin. As a result, an authenticated user with the editor role can create a new account with administrative privileges, leading to full administrative access and complete compromise of the CMS. This issue has been fixed in version 2.3.4.
Published: 2026-02-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-34p4-7w83-35g2 Formwork Improperly Managed Privileges in User creation
History

Tue, 03 Mar 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Formwork Project
Formwork Project formwork
CPEs cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:*
Vendors & Products Formwork Project
Formwork Project formwork

Wed, 25 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Getformwork
Getformwork formwork
Vendors & Products Getformwork
Getformwork formwork

Sat, 21 Feb 2026 05:30:00 +0000

Type Values Removed Values Added
Description Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to assign highly privileged roles such as admin. As a result, an authenticated user with the editor role can create a new account with administrative privileges, leading to full administrative access and complete compromise of the CMS. This issue has been fixed in version 2.3.4.
Title Formwork Improperly Manages Privileges During User Creation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Formwork Project Formwork
Getformwork Formwork
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-24T19:01:22.284Z

Reserved: 2026-02-18T19:47:02.155Z

Link: CVE-2026-27198

cve-icon Vulnrichment

Updated: 2026-02-24T19:01:15.608Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-21T06:17:00.543

Modified: 2026-03-03T17:33:54.540

Link: CVE-2026-27198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-23T14:32:44Z

Weaknesses