LiveActive security incident?Get immediate response
CVE Record

CVE-2026-34427: Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save

Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super Administrator privileges, enabling plugin upload functionality for remote code execution.

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

An authenticated user of Vvveb versions before 1.0.8.1 can reportedly change a protected account setting and become a Super Administrator. That access enables plugin uploads, which could lead to server compromise, data theft, alteration, or service disruption.

Executive priority

Prioritize remediation promptly because one compromised ordinary account could become full administrative and potentially server-level access. Internet-facing deployments with multiple or untrusted users should receive the highest urgency. Investigate for role and plugin changes, but do not treat vulnerability presence alone as evidence of compromise.

Technical view

CVE-2026-34427 is a CWE-915 privilege-escalation flaw in the admin user profile save endpoint. Insufficient filtering allows a low-privileged authenticated user to modify their role identifier. The supplied CVSS 3.1 score is 8.8, reflecting network access, low complexity, no user interaction, and high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is limited to Vvveb deployments before 1.0.8.1 where an attacker can authenticate as a lower-privileged user. Risk is greater for internet-accessible administration interfaces and environments allowing untrusted users to hold accounts. The supplied affected-version metadata is inconsistent, so confirm versions against vendor guidance.

Exploitation context

The attack requires an authenticated account but reportedly needs no victim interaction. Successful escalation can expose plugin-upload capabilities associated with remote code execution. The source bundle marks this CVE as absent from KEV and provides no evidence of active exploitation; public exploit availability is not established.

Researcher notes

The reported root cause is unsafe binding of profile request fields to an account object. The cited patch and 1.0.8.1 release support the remediation boundary. However, the bundle’s structured affected entry lists a commit identifier and defaults other versions to unaffected, conflicting with the title’s “prior to 1.0.8.1” scope; validate exact applicability with upstream records.

Mitigation direction

  • Upgrade Vvveb to version 1.0.8.1 or later after confirming vendor guidance and compatibility.
  • Restrict administrative interface access to trusted networks or authenticated access gateways until upgraded.
  • Disable unnecessary or untrusted low-privileged accounts pending remediation.
  • Review and remove unauthorized administrator accounts, roles, and plugins.

Validation and detection

  • Inventory Vvveb deployments and confirm each installed version using reliable application or package records.
  • Verify profile updates cannot modify privileged role fields for low-privileged users.
  • Review account and audit records for unexpected role changes or newly created administrators.
  • Inspect plugin installation records and server changes for unauthorized activity.
  • Confirm administrative interfaces are not unnecessarily exposed to the internet.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-915: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

Privilege behavior lookup

The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-34427 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
4Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H2.85.9VulnCheck
8.7CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

8.7High
CVSS 4.0 vector shape for CVE-2026-34427Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
givanzVvveb0, 0eca14af50f038915b8bf7ceec2becf6b6720b0aunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-915 · source CWE mapping

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Improperly Controlled Modification of Dynamically-Determined Object Attributes represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.