← Vulnerability feed

Vulnerability record · CVE-2023-49931 · published 29 February 2024

CVE-2023-49931: Couchbase server improper access control vulnerability

Couchbase · Couchbase Server

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

9.8 CVSS 3.1 Critical EPSS 0.90% · top 41.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-0519Google Chrome V8 out-of-bounds memory accessChrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger…KEVEPSS 3.8%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2023-2033Google Chrome V8 type confusion enables heap corruptionCVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap cor…KEVEPSS 41%analysed9.8CVE-2023-49930Couchbase server improper access control vulnerabilityAn issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.EPSS 0.90%9.8CVE-2021-35943Couchbase server improper authentication vulnerabilityCouchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…EPSS 1.1%9.8CVE-2020-24719Couchbase server os command injection vulnerabilityExposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (…EPSS 23%9.8CVE-2020-9039Couchbase server incorrect default permissions vulnerabilityCouchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an…EPSS 3.9%9.8CVE-2019-11495Couchbase server vulnerabilityIn Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PR…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-49931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.