Couchbase Server User Creation Vulnerability for Security Admins with Admin Role Access

Vulnerability

A vulnerability exists in Couchbase Server versions 7.6.x prior to 7.6.3, allowing users with the security_admin_local role to create new users in groups assigned the admin role.

Impact

Exploitation of this vulnerability could lead to unauthorized user creation with admin privileges, potentially allowing for elevated access and control within the Couchbase Server environment.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.