๐Ÿ” CVE Alert

CVE-2026-85177

MEDIUM 5.4

CRMEB through 6.0.0 Unauthorized Message Modification via edit_message

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, look, and uid to delete, mark read, or reassign victim notifications without authorization.

CWE CWE-639
Vendor crmeb
Product crmeb
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for crmeb crmeb

Be the first to know when new medium vulnerabilities affecting crmeb crmeb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

crmeb / CRMEB
0 โ‰ค 6.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/crmeb/CRMEB/issues/120 github.com: https://github.com/crmeb/CRMEB github.com: https://github.com/crmeb/CRMEB/blob/v6.0.0/crmeb/app/api/controller/v1/user/MessageSystemController.php vulncheck.com: https://www.vulncheck.com/advisories/crmeb-through-6.0.0-unauthorized-message-modification-via-edit-message

Credits

๐Ÿ” George Chen