Detects Winter CMS installations vulnerable to authenticated backend privilege escalation in winter/wn-backend-module <1.0.477, 1.1.0–1.1.11, and 1.2.0–1.2.11. Winter Storm's FormController save pipeline routes posted attributes through setModelAttributes(), which performs direct property assignment ($model->$attr = $value) and therefore bypasses Eloquent's $guarded array on the Backend User model. Because the self-redirect in the Users controller only guards the GET path of update(), any authenticated backend user can POST onSave to /backend/backend/users/update/{own-id} with User[permissions][...]=1 — the 'update' form context exposes the permissions field and grants the attacker arbitrary backend permissions they did not previously hold. CVSS 9.9. Patched in 1.0.477/1.1.12/1.2.12 by a beforeSave() hook on the User model that throws AuthorizationException for self-edits of role_id/is_superuser/permissions, edits to other users without backend.manage_users, and any non-superuser save touching a superuser record.
Is your app exploitable through CVE-2026-27591?
Scan your domain free