CVE-2026-1203 is an improper authentication vulnerability affecting CRMEB up to version 5.6.3, specifically within the remoteRegister function of the JSON Token Handler component. This flaw allows a remote attacker to manipulate the 'uid' argument, potentially bypassing authentication. While the attack complexity is high and exploitability is difficult, successful exploitation could lead to high impact on confidentiality, integrity, and availability. Although no active exploitation is reported, public exploit code exists, and the vulnerability has garnered significant community discussion, indicating potential future risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.6.3CPE matchmatch criteria | cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.