PT-2026-65089 · Unknown · Ekushey Project Manager Crm

CVE-2026-66028

·

Published

2026-07-27

·

Updated

2026-07-28

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ekushey Project Manager CRM versions prior to 5.1
Description A missing uniqueness constraint allows authenticated administrators to create duplicate client accounts using identical email and password credentials. The lack of enforcement on the email field enables the creation of conflicting account states where multiple accounts share the same email address but have different passwords, leading to unpredictable authentication behavior and unauthorized account access.
Recommendations Update Ekushey Project Manager CRM to a version newer than 5.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66028

Affected Products

Ekushey Project Manager Crm