Server-Side Request Forgery Vulnerability in crmeb_java Product from crmeb
CVE-2026-10771
Key Information:
- Vendor
Crmeb
- Status
- Vendor
- CVE Published:
- 3 June 2026
Badges
What is CVE-2026-10771?
A vulnerability exists in the crmeb_java 1.4 that could allow an attacker to exploit the RestTemplate function to perform server-side request forgery. The issue is located in the RestTemplateUtil.java file, specifically within the base64 Qrcode Endpoint. By manipulating the URL argument, an unauthorized entity could potentially invoke internal services, leading to unauthorized access and data exposure. This vulnerability has been publicly disclosed, and timely remediation is critical to protect applications from these types of attacks.
Affected Version(s)
crmeb_java 1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
