GHSA-34p4-7w83-35g2

Suggest an improvement
Source
https://github.com/advisories/GHSA-34p4-7w83-35g2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-34p4-7w83-35g2/GHSA-34p4-7w83-35g2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-34p4-7w83-35g2
Aliases
Published
2026-02-19T20:31:07Z
Modified
2026-02-23T23:43:41.661022Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Formwork Improperly Managed Privileges in User creation
Details

Summary

The application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has sufficient privileges to assign highly privileged roles such as admin. As a result, an authenticated user with the editor role can create a new account with administrative privileges, leading to full administrative access and complete compromise of the CMS.

Impact

Successful exploitation allows an attacker to: - Gain full administrative control over the CMS. - Access all site data and user information.
- Modify system configuration and security settings. - Create, modify, or delete any user account, including legitimate administrators.

Patches

Formwork 2.3.4 properly assigns roles on user creation.

Database specific
{
    "nvd_published_at": "2026-02-21T06:17:00Z",
    "github_reviewed_at": "2026-02-19T20:31:07Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-269"
    ]
}
References

Affected packages

Packagist / getformwork/formwork

Package

Name
getformwork/formwork
Purl
pkg:composer/getformwork/formwork

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.3.4

Affected versions

2.*
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.3.2
2.3.3

Database specific

last_known_affected_version_range
"<= 2.3.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-34p4-7w83-35g2/GHSA-34p4-7w83-35g2.json"