SB20260728104 - Path traversal in EspoCRM
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: CVE-2026-63130)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to modify or delete arbitrary JSON files accessible to the application.
The vulnerability exists due to path traversal in the administrative Label Manager functionality when processing file paths. A remote privileged user can supply a crafted path to modify or delete arbitrary JSON files accessible to the application.
Reading affected files does not impact the CVSS confidentiality metric, and exploitation is subject to server configuration and filesystem permissions.
Remediation
Install update from vendor's website.