Authentication Bypass in CRMEB by CRMEB
CVE-2026-85212
8.7HIGH
What is CVE-2026-85212?
CRMEB has a vulnerability allowing an authentication bypass due to a flaw in the verifyAuth() method of SystemRoleServices.php. This loophole permits sub-administrators and roles without explicit permissions to access restricted admin endpoints, leading to potential unauthorized actions. The issue arises from inadequate role checks that always validate requests, compromising system security significantly.
Affected Version(s)
CRMEB 0 <= 6.0.0
