CVE-2026-23698
Vtiger Vtiger CRM
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely si...
- CVSS
- 8.6
- EPSS
- 0.87% 55.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08