CVE-2026-27591Disclosure(wintercms / winter)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch wintercms winter systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access. This vulnerability is fixed in 1.0.477, 1.1.12, and 1.2.12.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • winter

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-11); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
winter

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-13: 2PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-13: 103-1103-13
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2General1
2026-03-132
Disclosure1Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Winter CMS urgently patches a critical 10.0 CVSS privilege escalation flaw (CVE-2026-27591) allowing low-level backend users to gain full system control. https://securityonline.info/winter-cms-urgently-patches-critical-10-0-cvss-privilege-escalation-flaw/ https://t.co/tL1wTNjZOO

    Post summary

    Winter CMS has released an urgent patch for CVE-2026-27591, a critical privilege escalation vulnerability that allows low‑level backend users to gain full system control; the article provides links for more details.

    01000288
    10.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27591 - Critical Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to e... https://www.thehackerwire.com/vulnerability/CVE-2026-27591/ https://t.co/ahnoIPnV7c

    Post summary

    The tweet reports the discovery of a critical vulnerability (CVE‑2026‑27591) affecting Winter CMS, but does not provide additional technical, exploit, or mitigation details.

    0000039
    134 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27591 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticat… https://www.cve.org/CVERecord?id=CVE-2026-27591

    Post summary

    The post references CVE-2026-27591 and notes legacy versions affected, but offers no PoC, exploit, patch, or technical details, making it a general mention.

    00000125
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27591: CRITICAL] Winter, a Laravel-based CMS, had a security flaw allowing authenticated backend users to escalate their access level through crafted requests. Versions 1.0.477, 1.1.12, and 1.2.12 ...#cve,CVE-2026-27591,#cybersecurity https://cvefind.com/CVE-2026-27591

    Post summary

    The post announces a CRITICAL access‑level escalation flaw in Winter (Laravel‑based CMS) affecting versions 1.0.477, 1.1.12, and 1.2.12, where authenticated backend users can elevate privileges via crafted requests.

    0000030
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27591: Winter: Privilege escalation by ... Perfect CVSS 10.0 because any backend login becomes instant admin through crafted role modification requests - Laravel'... https://zerodaysignal.com/vulnerability/CVE-2026-27591 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new CVE-2026-27591 vulnerability in Laravel, detailing a privilege escalation vector and a CVSS 10.0 score, and provides a link to further information, without mentioning active exploitation or a patch.

    0000054
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwintercmswinter---

Explore more