CVE-2026-95263

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.

Published 2026-10-05. Last modified 2026-10-06.