Vulnerability record · CVE-2022-24706 · published 26 April 2022
CVE-2022-24706: Apache CouchDB default install allows unauthenticated admin access
Apache · Couchdb
Apache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installation and obtain admin privileges. Because the flaw is in the default configuration rather than a coding error, any exposed instance that was not hardened per the documentation is at risk. It matters because admin access to CouchDB can be chained to remote code execution, as shown in public exploit write-ups.
Description
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable admin takeover with public exploit code, KEV listing and very high EPSS probability.
What it is
Apache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installation and obtain admin privileges. Because the flaw is in the default configuration rather than a coding error, any exposed instance that was not hardened per the documentation is at risk. It matters because admin access to CouchDB can be chained to remote code execution, as shown in public exploit write-ups.
Impact
An attacker gains full administrative control of the CouchDB instance without credentials, which can lead to data theft, configuration changes and remote code execution on the host.
Attack surface
Reachable over the network via the CouchDB HTTP/Erlang interfaces; the CVSS vector shows no privileges and no user interaction required. Exposure depends on the instance being reachable and left with default or otherwise improper security settings.
Exploitation
Listed in CISA KEV since 2022-08-25 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.925 (99.8th percentile). Multiple references are tagged Exploit, including public remote code execution write-ups.
What to do
- Upgrade Apache CouchDB to 3.2.2 or later.
- If immediate upgrade is not possible, restrict network access to CouchDB with a firewall or bind it to trusted interfaces only.
- Set a strong admin password and follow the vendor hardening guidance for cluster and installation setup.
- Remove or block exposure of CouchDB management and Erlang ports to untrusted networks.
- Audit existing installations for default or weak credentials and rotate any exposed secrets.
Detection
- Review CouchDB access logs for unauthenticated requests to admin or configuration endpoints from unexpected sources.
- Monitor for creation of new admin users or changes to CouchDB configuration outside change windows.
- Alert on outbound or host-level activity consistent with Erlang cookie abuse or unexpected process execution on CouchDB hosts.
- Scan the network for internet- or broadly reachable CouchDB instances and verify their version and authentication settings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-24706 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apache CouchDB Insecure Default Initialization of Resource Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-24706 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24706), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.