7.6

CVE-2025-46619

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Couchbase ≫ Couchbase Server Version >= 2.0.0 < 7.2.7
   Microsoft ≫ Windows Version -
Couchbase ≫ Couchbase Server Version >= 7.6.0 < 7.6.4
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.387
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://docs.couchbase.com/server/current/release-notes/relnotes.html
Release Notes
https://forums.couchbase.com/tags/security
Vendor Advisory
https://www.couchbase.com/alerts/
Vendor Advisory