PT-2026-56207 · Unknown+1 · Vtiger Crm+1

·

CVE-2026-23697

·

Published

2026-03-21

·

Updated

2026-07-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vtiger CRM versions prior to 8.4.0
Description An authenticated file upload issue exists in the Documents module that allows low-privileged users to achieve remote code execution. This occurs because the extension denylist in config.inc.php omits the .phar extension, enabling the upload of files containing arbitrary PHP code. These files are stored with their original extension in a web-accessible directory. Furthermore, on Apache 2.4 deployments, a misconfigured .htaccess file using Apache 2.2 syntax is ignored, which allows unauthenticated HTTP requests to execute the uploaded PHP payload.
Recommendations Update Vtiger CRM to version 8.4.0 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09469
CVE-2026-23697

Affected Products

Apache
Vtiger Crm