OVERVIEW CVE-2026-33733 affects EspoCRM, an open-source customer relationship management application, in versions prior to 9.3.4. The vulnerability exists in the admin template management endpoints, which fail to properly validate or normalize user-supplied name and scope parameters before using them in file path construction. This allows authenticated administrators to employ path traversal techniques using "../" sequences to escape the intended template directory and access arbitrary files on the system. SEVERITY This vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring high-level administrative privileges. The attack requires no user interaction and results in high confidentiality, integrity, and availability impacts. An authenticated admin can read, create, overwrite, or delete arbitrary files that resolve to body.tpl or subject.tpl within the web application user's filesystem permissions, potentially leading to data theft, system compromise, or denial of service. EXPLOITATION STATUS The vulnerability is not currently tracked on the Known Exploited Vulnerabilities catalog and shows no indication of active exploitation in the wild. While the EPSS score of 0.000760000 indicates lower exploitability relative to other CVEs, the issue requires administrative access, which naturally limits its attack surface. EspoCRM version 9.3.4 and later contain the necessary fixes and should be prioritized for deployment in organizations running affected versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3.4CPE matchmatch criteria | cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.