# CVE-2022-24706

## Summary

- **CVE ID:** CVE-2022-24706
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-1188
- **Published:** Apr 26, 2022
- **Last Modified:** Sep 16, 2026

## Description

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

## Affected Products

- Apache Software Foundation — Apache CouchDB (Apache CouchDB)

## References

- [CNA](https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00)
- [CNA](https://docs.couchdb.org/en/3.2.2/setup/cluster.html)
- [CNA](http://www.openwall.com/lists/oss-security/2022/04/26/1)
- [CNA](http://www.openwall.com/lists/oss-security/2022/05/09/1)
- [CNA](http://www.openwall.com/lists/oss-security/2022/05/09/3)
- [CNA](http://www.openwall.com/lists/oss-security/2022/05/09/4)
- [CNA](http://www.openwall.com/lists/oss-security/2022/05/09/2)
- [CNA](http://packetstormsecurity.com/files/167032/Apache-CouchDB-3.2.1-Remote-Code-Execution.html)
- [CNA](https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd)
- [CNA](http://packetstormsecurity.com/files/169702/Apache-CouchDB-Erlang-Remote-Code-Execution.html)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24706)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 94.39%
- **EPSS Percentile:** 100.0

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Aug 25, 2022
- **Due Date:** Sep 15, 2022

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._