What happened
Vertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 45019Apache CouchDB - Arbitrary Command Execution (Metasploit)Metasploit2018-07-13VerifiedExploit-DB 44913Apache CouchDB < 2.1.0 - Remote Code ExecutionCody Zacharias2018-06-20VerifiedSploitusVertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.KitPloit2026-09-04T03:05:01Candidatekitploit.comVertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.ru2026-09-04T03:05:01CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.