Junglewise Threat Intelligence

CVE-2026-85040: ZhongBangKeJi CRMEB remote code execution in custom scheduled tasks

CVE-2026-85040 · Severity: medium · CVSS 4.7 · Published 2026-09-03

Technologies: ZhongBangKeJi CRMEB. Vendors: ZhongBangKeJi.

Executive brief

CRMEB is a popular open-source e-commerce and CRM system. The custom scheduled task feature allows authenticated backend administrators to define code that runs on a timer. A weakness in input validation enables authenticated attackers to execute arbitrary code on the server by injecting malicious payloads into the customCode parameter, leading to complete system compromise.

Technical details

The vulnerability is a remote code execution flaw in the custom scheduled task feature of CRMEB. An authenticated backend administrator can submit arbitrary PHP code via the customCode parameter to POST /adminapi/system/crontab/save. The application applies only a blacklist-based filter (isSafePhpCode) which is insufficient to prevent code injection. The code is then stored and executed later via eval() in CrontabRunServices.php when the scheduled task runs. Attack requires prior admin/backend authentication and access to the administrative interface. An attacker with backend access can execute arbitrary OS commands and PHP code with the privileges of the web server process. The vendor documented this as debug-only behavior but the weak blacklist provides no genuine RCE protection.

Affected products

  • ZhongBangKeJi CRMEB up to 6.0.0

Timeline

  • 2026-09-03: disclosed
  • other: Exploit made publicly available

References