Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-23698— Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload

Quick assessment

Affected
Vtiger Vtiger CRM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Vtiger CRM是美国Vtiger公司开源的一套基于SugarCRM开发的客户关系管理系统(CRM)。该管理系统提供管理、收集、分析客户信息等功能。 Vtiger CRM 8.4.0及之前版本存在任意文件上传漏洞,该漏洞源于管理员模块导入功能中未对文件类型进行充分验证,允许管理员级攻击者通过ModuleManager导入功能上传特制zip压缩包,将文件解压至web根目录下的modules目录,从而上传任意PHP文件。

CVSS 7.2 · High EPSS 1.23% · P67

Affected Version Matrix 1

VendorProduct Version RangeStatus
Vtiger Vtiger CRM ≤ 8.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-23698

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
Source: CVE Program / CVE List V5
Vulnerability Description
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5
Vulnerability Title
Vtiger CRM 任意文件上传漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vtiger CRM是美国Vtiger公司开源的一套基于SugarCRM开发的客户关系管理系统(CRM)。该管理系统提供管理、收集、分析客户信息等功能。 Vtiger CRM 8.4.0及之前版本存在任意文件上传漏洞,该漏洞源于管理员模块导入功能中未对文件类型进行充分验证,允许管理员级攻击者通过ModuleManager导入功能上传特制zip压缩包,将文件解压至web根目录下的modules目录,从而上传任意PHP文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Vtiger Vtiger CRM 0 ~ 8.4.0 -

II. Public POCs for CVE-2026-23698

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23698

登录查看更多情报信息。

Vendor Advisories for CVE-2026-23698 (1)

Vendor Pages for CVE-2026-23698 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-23698

No comments yet


Leave a comment