CVE-2022-48365: Ibexa Digital Experience Platform

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.

Affected products

  • Ibexa Digital Experience Platform: from 3.3.0, before 3.3.28 (fixed in 3.3.28); from 4.2.0, before 4.2.3 (fixed in 4.2.3)
  • Ibexa Ez Platform: from 2.5.0, before 2.5.31 (fixed in 2.5.31)
  • Ibexa Ez Platform Kernel: from 1.3.0, before 1.3.26 (fixed in 1.3.26); from 7.5.0, before 7.5.30 (fixed in 7.5.30)

Published 2023-03-12. Last modified 2026-06-17.