CVE-2026-95263
EUVD-2026-9278305.10.2026, 20:17
Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.