Sceawere

Vulnerability Detail

CVE-2026-62083UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Creator LMS Subscriber Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
WPFunnels
Product
Creator LMS
Attack Type
CWE-1284 Improper Validation of Specified Quantity in Input
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-30T13:17:19.587Z",
  "pubdate": "2026-09-30T13:17:19.587Z",
  "executiveSummary": "The vulnerability identified in Creator LMS versions 1.2.19 and earlier is categorized as a Subscriber-level vulnerability, indicating a failure in authorization enforcement within the application's user role management.\nThis flaw allows a user authenticated with low-level 'Subscriber' privileges to perform actions or access data restricted to higher-privileged roles, such as administrators or instructors.\nThe vulnerability stems from improper access control checks where the application fails to validate the user's session role against the requested backend function or administrative interface.\nAttackers with valid, low-privileged accounts can exploit this flaw to execute unauthorized operations, which may include modifying system configurations, managing course content, or potentially accessing sensitive student information.\nThe risk is significant due to the potential for unauthorized privilege escalation, which compromises the integrity and confidentiality of the learning management system.\nExploitation requires the attacker to possess an active, authenticated subscriber account on the target system; no advanced social engineering or external network access beyond the application interface is inherently required.",
  "technicalDetails": "The root cause of this vulnerability lies in the inadequate implementation of server-side authorization checks for specific administrative endpoints within the Creator LMS software. In versions 1.2.19 and earlier, the application fails to enforce strict role-based access control (RBAC) on critical functions that are meant to be restricted to administrative or elevated roles.\nWhen a user with a 'Subscriber' role interacts with the application, the system fails to verify whether the session token associated with the request possesses the necessary permission bits to execute the requested action. This is characteristic of an Insecure Direct Object Reference (IDOR) or a missing function-level access control vulnerability, where the application assumes that if a user is authenticated, they are authorized to perform any action available in the UI.\nThe attack flow begins with an attacker authenticating to the platform as a standard subscriber. Upon identifying the URL patterns or API endpoints associated with administrative operations, the attacker can manipulate request parameters or directly invoke these functions via POST/GET requests. Because the server-side code relies solely on the presence of a session rather than verifying the specific privilege level, the application processes the unauthorized request.\nFrom a technical standpoint, the vulnerable component is the backend request handling logic that facilitates user management or course administration. The lack of middleware or server-side decorators that perform 'IsUserAuthorized()' checks on these endpoints allows the request to reach the logic layer, where sensitive database queries or system configuration changes are executed.\nThe post-exploitation impact is severe. Since the attacker is operating within the context of an authenticated session, they can perform CRUD (Create, Read, Update, Delete) operations on resources that should be protected. This includes, but is not limited to, escalating privileges to administrator, altering course materials, deleting users, or exfiltrating sensitive organizational data hosted within the LMS.\nThis vulnerability is classified as remotely exploitable, requiring no specific network conditions other than reachability to the application's web interface. The exploitation method is consistent and does not require complex bypass techniques beyond standard HTTP parameter manipulation."
}
CVE-2026-62083: Creator LMS Subscriber Privilege Escalation (MEDIUM Severity, CVSS: 5.4) | Sceawere