← Vulnerability feed

Vulnerability record · CVE-2020-9039 · published 22 February 2020

CVE-2020-9039: Couchbase server incorrect default permissions vulnerability

Couchbase · Couchbase Server

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

9.8 CVSS 3.1 Critical EPSS 3.9% · top 10.0% CWE-276 · Incorrect default permissions
9.8CVSS 3.1 base score, v2 7.5
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-0519Google Chrome V8 out-of-bounds memory accessChrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger…KEVEPSS 3.8%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2023-2033Google Chrome V8 type confusion enables heap corruptionCVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap cor…KEVEPSS 41%analysed9.8CVE-2023-49930Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2023-49931Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2021-35943Couchbase server improper authentication vulnerabilityCouchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…EPSS 1.1%9.8CVE-2020-24719Couchbase server os command injection vulnerabilityExposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…EPSS 23%9.8CVE-2019-11495Couchbase server vulnerabilityIn Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2020-9039), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.