Junglewise Threat Intelligence

CVE-2026-79426: CRMEB arbitrary file deletion in video_data_save endpoint

CVE-2026-79426 · Severity: high · CVSS 7.2 · Published 2026-09-04

Executive brief

CRMEB is an open-source e-commerce platform used to build online stores and shopping applications. An authenticated attacker can delete arbitrary files from the server through a crafted request to the video file management endpoint, potentially causing data loss or service disruption.

Technical details

This vulnerability exists in the /adminapi/file/video_data_save component of CRMEB v6.0.0 and allows authenticated users to perform arbitrary file deletion via a specially crafted POST request. The vulnerability is rooted in improper input validation or path traversal controls in the file deletion logic. An authenticated attacker with access to the admin API can exploit this to delete critical application files or user-uploaded content. No information on patch availability was provided in the advisory.

Affected products

  • CRMEB CRMEB 6.0.0

Timeline

  • 2026-09-04: disclosed

References