Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85212

HIGH NVD
CVSS Score 8.3
Severity HIGH
Published Sep 03, 2026
Vendor unknown

Description

CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.

References