Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33733

23
FAUCET Score

OVERVIEW CVE-2026-33733 affects EspoCRM, an open-source customer relationship management application, in versions prior to 9.3.4. The vulnerability exists in the admin template management endpoints, which fail to properly validate or normalize user-supplied name and scope parameters before using them in file path construction. This allows authenticated administrators to employ path traversal techniques using "../" sequences to escape the intended template directory and access arbitrary files on the system. SEVERITY This vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring high-level administrative privileges. The attack requires no user interaction and results in high confidentiality, integrity, and availability impacts. An authenticated admin can read, create, overwrite, or delete arbitrary files that resolve to body.tpl or subject.tpl within the web application user's filesystem permissions, potentially leading to data theft, system compromise, or denial of service. EXPLOITATION STATUS The vulnerability is not currently tracked on the Known Exploited Vulnerabilities catalog and shows no indication of active exploitation in the wild. While the EPSS score of 0.000760000 indicates lower exploitability relative to other CVEs, the issue requires administrative access, which naturally limits its attack surface. EspoCRM version 9.3.4 and later contain the necessary fixes and should be prioritized for deployment in organizations running affected versions.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.3.4CPE matchmatch criteria
cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 13th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / espocrm/espocrm/security/advisories/GHSA-44c3-xjfp-3jrh
ExploitMitigationVendor Advisory