Path traversal in EspoCRM - CVE-2026-63130

 

Path traversal in EspoCRM - CVE-2026-63130

Published: July 28, 2026


Vulnerability identifier: #VU139914
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-63130
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: EspoCRM
Affected software:
EspoCRM

Detailed vulnerability description

The vulnerability allows a remote user to modify or delete arbitrary JSON files accessible to the application.

The vulnerability exists due to path traversal in the administrative Label Manager functionality when processing file paths. A remote privileged user can supply a crafted path to modify or delete arbitrary JSON files accessible to the application.

Reading affected files does not impact the CVSS confidentiality metric, and exploitation is subject to server configuration and filesystem permissions.


How to mitigate CVE-2026-63130

Install security update from vendor's website.

Sources