# CVE-2018-8007 — Apache CouchDB

> As of 2024-09-16, CVE-2018-8007 is a HIGH-severity vulnerability in Apache CouchDB, CVSS v3.1 7.2, EPSS 11.6% (95.5th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2018-8007, most recently “RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation”.

**Last updated:** 2024-09-16

## What is CVE-2018-8007?

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows an existing CouchDB admin user to gain arbitrary remote code execution, bypassing already disclosed CVE-2017-12636. Mitigation: All users should upgrade to CouchDB releases 1.7.2 or 2.1.2.

The record classifies CVE-2018-8007 under weakness class [CWE-20](https://intel.threadlinqs.com/cwe/CWE-20). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs high-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 3008 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 7.2 — HIGH (`CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 11.6% probability of exploitation in the next 30 days, higher than 95.5% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 9.4/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2018-07-11, last modified 2024-09-16

## Is CVE-2018-8007 being exploited?

Weaponised exploit code for CVE-2018-8007 is publicly available. 1 public proof-of-concept repository is tracked for this identifier.

- [trickest/cve](https://github.com/trickest/cve/blob/main/2018/CVE-2018-8007.md) (trickest)

## Affected products and versions

- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation): Apache CouchDB

## How to fix CVE-2018-8007

No vendor patch reference has been recorded for CVE-2018-8007 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2018-8007

1 tracked threat in the Threadlinqs corpus references CVE-2018-8007, either in the campaign’s CVE list or as an indicator on the campaign record.

- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — CRITICAL · 2026-06-30

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories. Last verified by Threadlinqs on 2026-07-09. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [security.gentoo.org — vendor advisory](https://security.gentoo.org/glsa/201812-06)
- [blog.couchdb.org](https://blog.couchdb.org/2018/07/10/cve-2018-8007/)
- [support.hpe.com](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03935en_us)
- [lists.fedoraproject.org — vendor advisory](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3JOUCX7LHDV4YWZDQNXT5NTKKRANZQW/)
- [lists.fedoraproject.org — vendor advisory (S5FPHVVU5KMRFKQTJPAM3TBGC7LKCWQS)](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S5FPHVVU5KMRFKQTJPAM3TBGC7LKCWQS/)

**Vulnerability database entry**

- [securityfocus.com — vdb entry](http://www.securityfocus.com/bid/104741)

**Mailing list and disclosure**

- [mail-archives.apache.org — mailing list](http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3c1439409216.6221.1531246856676.JavaMail.Joan%40RITA%3e)
- [mail-archives.apache.org — mailing list (%3C1699016538.6219.1531246785603.JavaMai)](http://mail-archives.apache.org/mod_mbox/couchdb-announce/201807.mbox/%3C1699016538.6219.1531246785603.JavaMail.Joan%40RITA%3E)

**Other references**

- [mdsec.co.uk](https://www.mdsec.co.uk/2018/08/advisory-cve-2018-8007-apache-couchdb-remote-code-execution/)

Canonical: https://intel.threadlinqs.com/cve/CVE-2018-8007
Full detection coverage and IOCs for threats exploiting CVE-2018-8007 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
