CVE-2023-50437: Couchbase Server

High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

Affected products

  • Couchbase Couchbase Server: from 2.0.0, before 7.2.4 (fixed in 7.2.4)

Published 2024-02-29. Last modified 2026-06-17.