← Vulnerability feed

Vulnerability record · CVE-2022-24706 · published 26 April 2022

CVE-2022-24706: Apache CouchDB default install allows unauthenticated admin access

Apache · Couchdb

Apache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installation and obtain admin privileges. Because the flaw is in the default configuration rather than a coding error, any exposed instance that was not hardened per the documentation is at risk. It matters because admin access to CouchDB can be chained to remote code execution, as shown in public exploit write-ups.

9.8 CVSS 3.1 Critical CISA KEV since 25 Aug 2022 EPSS 93% · top 0.2% CWE-1188 · Insecure default initialization
9.8CVSS 3.1 base score, v2 10.0
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
21References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable admin takeover with public exploit code, KEV listing and very high EPSS probability.

What it is

Apache CouchDB before 3.2.2 ships with an insecure default initialization that lets an unauthenticated attacker reach an improperly secured installation and obtain admin privileges. Because the flaw is in the default configuration rather than a coding error, any exposed instance that was not hardened per the documentation is at risk. It matters because admin access to CouchDB can be chained to remote code execution, as shown in public exploit write-ups.

Impact

An attacker gains full administrative control of the CouchDB instance without credentials, which can lead to data theft, configuration changes and remote code execution on the host.

Attack surface

Reachable over the network via the CouchDB HTTP/Erlang interfaces; the CVSS vector shows no privileges and no user interaction required. Exposure depends on the instance being reachable and left with default or otherwise improper security settings.

Exploitation

Listed in CISA KEV since 2022-08-25 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.925 (99.8th percentile). Multiple references are tagged Exploit, including public remote code execution write-ups.

What to do

  • Upgrade Apache CouchDB to 3.2.2 or later.
  • If immediate upgrade is not possible, restrict network access to CouchDB with a firewall or bind it to trusted interfaces only.
  • Set a strong admin password and follow the vendor hardening guidance for cluster and installation setup.
  • Remove or block exposure of CouchDB management and Erlang ports to untrusted networks.
  • Audit existing installations for default or weak credentials and rotate any exposed secrets.

Detection

  • Review CouchDB access logs for unauthenticated requests to admin or configuration endpoints from unexpected sources.
  • Monitor for creation of new admin users or changes to CouchDB configuration outside change windows.
  • Alert on outbound or host-level activity consistent with Erlang cookie abuse or unexpected process execution on CouchDB hosts.
  • Scan the network for internet- or broadly reachable CouchDB instances and verify their version and authentication settings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-24706 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apache CouchDB Insecure Default Initialization of Resource Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2022/04/26/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/2 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/3 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/4 Mailing ListPatchThird Party Advisory
https://docs.couchdb.org/en/3.2.2/setup/cluster.html Broken LinkProduct
https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 Mailing ListVendor Advisory
https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd ExploitThird Party Advisory
http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2022/04/26/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/2 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/3 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/05/09/4 Mailing ListPatchThird Party Advisory
https://docs.couchdb.org/en/3.2.2/setup/cluster.html Broken LinkProduct
https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00 Mailing ListVendor Advisory
https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd ExploitThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24706 US Government Resource

Track CVE-2022-24706 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1955Apache couchdb missing authentication for critical function vulnerabilityCouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…EPSS 1.8%9.8CVE-2017-12635Apache CouchDB privilege escalation via duplicate JSON roles keysApache CouchDB before 1.7.0 and 2.x before 2.1.1 parses JSON differently in its Erlang and JavaScript layers, so a _users document containing duplica…EPSS 100%analysed7.8CVE-2018-14889Apache couchdb improper input validation vulnerabilityCouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.EPSS 0.56%7.8CVE-2016-8742Apache couchdb permissions and access controls vulnerabilityThe Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…EPSS 2.0%7.3CVE-2021-38295Apache couchdb cross-site scripting vulnerabilityIn Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB…EPSS 2.5%7.2CVE-2018-17188Apache couchdb vulnerabilityPrior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilit…EPSS 3.2%7.2CVE-2018-11769Apache couchdb vulnerabilityCouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied con…EPSS 8.2%7.2CVE-2018-8007Apache couchdb improper input validation vulnerabilityApache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2022-24706), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.