CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests. | |
| Title | CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check | |
| First Time appeared |
Crmeb
Crmeb crmeb |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Crmeb
Crmeb crmeb |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:12:23.174Z
Reserved: 2026-09-03T13:44:51.551Z
Link: CVE-2026-85212
No data.
Status : Received
Published: 2026-09-03T15:17:40.417
Modified: 2026-09-03T15:17:40.417
Link: CVE-2026-85212
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:45:05Z
Weaknesses