PT-2026-56208 · Unknown · Vtiger Crm

·

CVE-2026-23698

·

Published

2026-03-21

·

Updated

2026-07-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vtiger CRM versions prior to 8.4.1
Description An authenticated remote code execution issue exists in the admin module import feature. Administrator-level attackers can upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function. The system extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. This allows attackers to place executable PHP files in the modules/ directory that are directly accessible via HTTP, bypassing the authentication and authorization layer because the web server resolves the path and invokes the PHP interpreter before the application routing layer is involved, creating a persistent web shell.
Recommendations Update Vtiger CRM to a version newer than 8.4.0. Restrict access to the ModuleManager import function to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09471
CVE-2026-23698

Affected Products

Vtiger Crm