Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33656

32
FAUCET Score

CVE-2026-33656 is a critical path traversal vulnerability affecting EspoCRM versions prior to 9.3.4. The vulnerability exists in the formula scripting engine, which allows authenticated administrators to manipulate the sourceId field on Attachment entities. This unsanitized input is subsequently concatenated directly into file paths, enabling attackers to redirect file operations to arbitrary locations within the web server's open_basedir scope. The vulnerability carries a CVSS 3.1 score of 9.1 CRITICAL with a network-based attack vector requiring high-level administrative privileges but no user interaction. The attack has wide-ranging impact across confidentiality, integrity, and availability, potentially allowing an attacker to read sensitive files, overwrite critical application files, or disrupt service availability. The EPSS score of 0.00054 indicates low near-term exploitation probability relative to other CVEs. There is no current evidence of active exploitation in the wild, and the vulnerability does not appear on CISA's Known Exploited Vulnerabilities catalog. The threat appears limited to known threat actors with administrative access to vulnerable systems. Organizations running EspoCRM should prioritize upgrading to version 9.3.4 or later to remediate this high-severity flaw, particularly if their deployments are internet-facing.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.3.4CPE matchmatch criteria
cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
39.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 27th percentile among its peer group of 462 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / espocrm/espocrm/security/advisories/GHSA-7922-x7cf-j54x
ExploitVendor Advisory