CVE-2026-33656 is a critical path traversal vulnerability affecting EspoCRM versions prior to 9.3.4. The vulnerability exists in the formula scripting engine, which allows authenticated administrators to manipulate the sourceId field on Attachment entities. This unsanitized input is subsequently concatenated directly into file paths, enabling attackers to redirect file operations to arbitrary locations within the web server's open_basedir scope. The vulnerability carries a CVSS 3.1 score of 9.1 CRITICAL with a network-based attack vector requiring high-level administrative privileges but no user interaction. The attack has wide-ranging impact across confidentiality, integrity, and availability, potentially allowing an attacker to read sensitive files, overwrite critical application files, or disrupt service availability. The EPSS score of 0.00054 indicates low near-term exploitation probability relative to other CVEs. There is no current evidence of active exploitation in the wild, and the vulnerability does not appear on CISA's Known Exploited Vulnerabilities catalog. The threat appears limited to known threat actors with administrative access to vulnerable systems. Organizations running EspoCRM should prioritize upgrading to version 9.3.4 or later to remediate this high-severity flaw, particularly if their deployments are internet-facing.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3.4CPE matchmatch criteria | cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.