Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.6epss 0.9%
from disclosure to weapon0 days
Published on NVDJul 7
1st PoCJul 7
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Vtiger · Vtiger CRMpublic PoCs found — 2
githubgithub.com/JivaSecurity/VTIGER-CRM-RCE-CVE-2026-23698★ 0cve_referencejivasecurity.com/writeups/vtiger-rce-module-import-cve-2026-23698unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.