CVE-2022-24706
Remote Code Execution Vulnerability in Packaging
- Published
- Apr 26, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- May 11, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
Sources
7I wrote a blog post about Apache CouchDB CVE-2022-24706 RCE Exploits
Proof-of-concept exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below. Demonstrates remote command execution via Erlang Distribution Protocol using default cookie authentication.
- CVE-2022-24706Scanner
Apache CouchDB 3.2.1 - Remote Code Execution (RCE) Checker
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.