๐Ÿ” CVE Alert

CVE-2026-85212

HIGH 8.3

CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.

CWE CWE-862
Vendor crmeb
Product crmeb
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for crmeb crmeb

Be the first to know when new high vulnerabilities affecting crmeb crmeb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

crmeb / CRMEB
0 โ‰ค 6.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/crmeb/CRMEB/issues/119 github.com: https://github.com/crmeb/CRMEB github.com: https://github.com/crmeb/CRMEB/blob/v6.0.0/crmeb/app/services/system/admin/SystemRoleServices.php vulncheck.com: https://www.vulncheck.com/advisories/crmeb-through-6.0.0-missing-authorization-via-inert-verifyauth-role-check

Credits

๐Ÿ” George Chen