{"id":"CVE-2026-85212","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-85212","summary":"CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check","details":"CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.","published":"2026-09-03T14:12:23.174Z","modified":"2026-09-04T03:47:26.786501353Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85212.json"},{"type":"PACKAGE","url":"https://github.com/crmeb/CRMEB"},{"type":"ARTICLE","url":"https://github.com/crmeb/CRMEB/blob/v6.0.0/crmeb/app/services/system/admin/SystemRoleServices.php"},{"type":"REPORT","url":"https://github.com/crmeb/CRMEB/issues/119"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85212"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/crmeb-through-6.0.0-missing-authorization-via-inert-verifyauth-role-check"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:47:26.786501353Z"}}