Unauthorized Message Modification in CRMEB by CRMEB Team
CVE-2026-85177

5.3MEDIUM

Key Information:

Vendor

Crmeb

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85177?

CRMEB versions up to 6.0.0 include a vulnerability in the edit_message handler of MessageSystemController.php that fails to validate message ownership effectively. This oversight allows authenticated users to manipulate arbitrary system inbox messages. Attackers are able to alter message properties, such as marking messages as read or deleting them without proper authorization, leading to potential misinformation and privacy concerns among users.

Affected Version(s)

CRMEB 0 <= 6.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.