CVE-2026-85212
EUVD-2026-7049003.09.2026, 15:17
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| crmeb | crmeb | 𝑥 ≤ 6.0.0 | CNA |
Common Weakness Enumeration