Authentication Bypass in CRMEB by CRMEB
CVE-2026-85212

8.7HIGH

Key Information:

Vendor

Crmeb

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85212?

CRMEB has a vulnerability allowing an authentication bypass due to a flaw in the verifyAuth() method of SystemRoleServices.php. This loophole permits sub-administrators and roles without explicit permissions to access restricted admin endpoints, leading to potential unauthorized actions. The issue arises from inadequate role checks that always validate requests, compromising system security significantly.

Affected Version(s)

CRMEB 0 <= 6.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.