CVE-2026-79426
7.2CRMEB · CRMEB
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via a crafted POST request.
Executive summary
An authenticated arbitrary file deletion vulnerability in CRMEB v6.0.0 allows attackers to remove critical system files, potentially causing severe operational disruption.
Vulnerability
The vulnerability exists in the /adminapi/file/video_data_save component, which fails to properly sanitize input, allowing an authenticated attacker to delete arbitrary files on the filesystem. This requires administrative-level privileges to trigger, but could lead to catastrophic system failure if critical configuration or system files are targeted.
Business impact
The ability to delete arbitrary files poses a significant risk to service availability and system stability. A CVSS score of 7.2 reflects the high impact on system availability, which could lead to prolonged downtime and the potential for an attacker to cripple the application environment.
Remediation
Immediate Action: Monitor for official updates from the CRMEB project and apply the latest version as soon as it becomes available to address the flawed component.
Proactive Monitoring: Review system file integrity and monitor administrative API logs for unusual file deletion activity or unexpected POST requests to the video_data_save endpoint.
Compensating Controls: Ensure that the application process runs with the least privilege necessary to limit the scope of file deletion if the application is compromised.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as attributed to the security advisory linked in the CVE record.
Analyst recommendation
The risk of arbitrary file deletion requires immediate attention to prevent malicious actors from causing irreversible damage to the application environment. Organizations should restrict administrative access to the API and monitor for suspicious behavior while awaiting a formal patch from the vendor.
More CRMEB CVEs
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.2 (3.1)
- Analyst report written
- Analyst report updated
- Published in the daily brief high section, early-warning entry