Executive brief
Pivotal CRM, a customer relationship management platform, contains a critical security flaw that allows attackers to take full control of the system. This issue occurred because a previous security update was incomplete, leaving a backdoor open for malicious commands to be executed remotely. If exploited, an attacker could steal sensitive customer data, disrupt business operations, or deploy ransomware across the corporate network.
Technical details
This vulnerability is a regression resulting from an incomplete patch for CVE-2026-39253. While the original fix replaced the unsafe .NET BinaryFormatter with Newtonsoft.Json, it incorrectly configured 'TypeNameHandling.Auto' without a SerializationBinder. This allows an attacker to provide a malicious JSON payload containing '$type' metadata to instantiate dangerous .NET gadget chains, such as ObjectDataProvider. The vulnerability resides in the 'Pivotal.Engine.Client.Services.Conversion.dll' component within the 'BinaryStringRepToObject' method. A remote, unauthenticated attacker can achieve full remote code execution (RCE) by sending a Base64-encoded JSON payload to the affected endpoint. The issue is resolved in Pivotal CRM 6.6.5.10 or by applying the updated 'Patch_CWE502_20260316.zip'.
Affected products
- Aurea (Pivotal) Pivotal CRM 6.6.4.08, systems using patch-ghi-15381-cwe-502-20251225.zip
Timeline
- 2025-12-25: patched: Initial incomplete patch released (patch-ghi-15381-cwe-502-20251225.zip)
- 2026-03-16: patched: Updated patch released (Patch_CWE502_20260316.zip)
- 2026-07-01: disclosed: CVE-2026-51947 published