Skip to content
← LibraryTechnique entry
DB-COUCHDB-RCEExecution

CouchDB Privilege Escalation (CVE-2017-12636)

Authenticated query-server config edit allows arbitrary OS commands as CouchDB user — historical but still common in legacy IoT stacks.

§ Where this technique fits

DB-COUCHDB-RCE is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.