Junglewise Threat Intelligence

CVE-2026-85212: CRMEB authentication bypass in SystemRoleServices

CVE-2026-85212 · Severity: high · CVSS 8.3 · Published 2026-09-03

Vendors: CRMEB.

Executive brief

CRMEB is an open-source e-commerce platform that provides admin role-based access controls to protect sensitive management features. A logic flaw in the authentication check allows sub-administrators and unprivileged accounts to bypass these restrictions and access protected admin endpoints they should not be able to reach, potentially compromising system integrity and exposing sensitive operations.

Technical details

The vulnerability is an authentication bypass in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches of a role-checking logic, rendering the permission check ineffective. The flawed conditional logic means that regardless of whether a user has valid admin roles or not, the method always permits access. Sub-administrators and accounts with no assigned roles can exploit this to reach restricted administrative endpoints. No authentication credentials are required beyond having any account in the system; the attack is purely logic-based within the application. Patches should implement proper conditional logic to reject requests from unprivileged accounts.

Affected products

  • CRMEB CRMEB v6.0.0 and likely earlier versions

Timeline

  • 2026-09-03: disclosed

References