Junglewise Threat Intelligence

CVE-2025-67887: 1C-Bitrix Remote Code Execution in Translate Module

CVE-2025-67887 · Severity: critical · CVSS 9.8 · Published 2026-05-08

Executive brief

1C-Bitrix, a popular content management system and business automation platform, contains a vulnerability in its Translate Module. An attacker with specific permissions can upload and execute malicious code on the server by bypassing file restrictions. This could lead to a complete takeover of the website, theft of customer data, or disruption of business operations.

Technical details

A Remote Code Execution (RCE) vulnerability exists in the Translate Module of 1C-Bitrix versions up to 25.100.500. The application fails to properly validate the contents of uploaded archives before extraction in the 'translate.asset.grabber' component. An attacker with 'SOURCE' and 'WRITE' permissions can upload a TAR archive containing a PHP shell and a crafted .htaccess file to bypass execution restrictions in temporary directories. Once extracted, the attacker can navigate to the uploaded PHP file to execute arbitrary commands. The vendor disputes this as a vulnerability, claiming it is intended functionality for high-privileged users.

Affected products

  • 1C-Bitrix 1C-Bitrix through 25.100.500

Timeline

  • 2025-10-22: other: Vendor notified
  • 2025-12-12: other: CVE identifier assigned
  • 2025-12-15: disclosed: Public disclosure by researcher
  • 2026-05-08: advisory: NVD publication

References