CVE-2026-95263: Feehi Feehi CMS vulnerability
Published Oct 5, 2026
·Updated
Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.
Affected Software
1 affected component
Feehi Feehi CMS=2.1.1
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A low-privilege backend administrator that has administrator-update permission can exploit it. The attacker must be able to access the backend administrator update functionality.
2
What access could an attacker gain?
The attacker can change the password of the built-in super administrator account, allowing them to take over that account.
3
Is knowledge of the current super administrator password required?
No. The affected update scenario allows the password to be changed without requiring the old password.