CVE-2022-50911: Bitrix24 - Remote Code Execution (RCE) (Authenticated)
Published Jan 13, 2026
·Updated
Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
Affected Software
1 affected component
Bitrix Bitrix24
Event History
Jan 13, 2026
CVE Published
via MITRE·10:51 PM
Rejected
via MITRE·10:51 PM
Data Sourced
via NVD·11:15 PM
Description
Jan 16, 2026
Rejected
via MITRE·02:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2022-50911?
CVE-2022-50911 is classified as a critical severity vulnerability due to its potential for authenticated remote code execution.
2
How do I fix CVE-2022-50911?
To fix CVE-2022-50911, update to the latest version of Bitrix24 that addresses this vulnerability.
3
Who is affected by CVE-2022-50911?
CVE-2022-50911 affects users of Bitrix24 who have access to the PHP command line admin interface.
4
What type of attacks can be performed using CVE-2022-50911?
Attackers can perform authenticated remote code execution attacks, allowing them to execute arbitrary system commands.
5
Is authentication required to exploit CVE-2022-50911?
Yes, exploitation of CVE-2022-50911 requires the attacker to be logged in to the Bitrix24 system.