CVE-2023-49931: Couchbase Server
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
Affected products
- Couchbase Couchbase Server: from 5.0.0, before 7.2.4 (fixed in 7.2.4)
Published 2024-02-29. Last modified 2026-06-17.