PT-2026-85046 · Crmeb · Crmeb

·

CVE-2026-85212

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions CRMEB versions prior to 6.0.0
Description An authentication bypass exists in the verifyAuth() function within SystemRoleServices.php. The issue stems from an inert role check that returns true regardless of the conditional branch taken. This allows sub-administrators and accounts without assigned roles to gain unauthorized access to restricted admin endpoints.
Recommendations Update to a version newer than 6.0.0. As a temporary mitigation, restrict access to the verifyAuth() function in SystemRoleServices.php.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85212

Affected Products

Crmeb