SB20260728104 - Path traversal in EspoCRM



SB20260728104 - Path traversal in EspoCRM

Published: July 28, 2026

Security Bulletin ID SB20260728104
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Path traversal (CVE-ID: CVE-2026-63130)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to modify or delete arbitrary JSON files accessible to the application.

The vulnerability exists due to path traversal in the administrative Label Manager functionality when processing file paths. A remote privileged user can supply a crafted path to modify or delete arbitrary JSON files accessible to the application.

Reading affected files does not impact the CVSS confidentiality metric, and exploitation is subject to server configuration and filesystem permissions.


Remediation

Install update from vendor's website.