PT-2026-85036 · Crmeb · Crmeb

·

CVE-2026-85177

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CRMEB through 6.0.0 fails to validate message ownership in the edit message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is del, look, and uid to delete, mark read, or reassign victim notifications without authorization.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85177

Affected Products

Crmeb