CVE-2026-1733: Zhong Bang CRMEB :uni tidyOrder improper authorization
A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/storeintegral/order/detail/:uni. The manipulation of the argument orderid leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1733?
The severity of CVE-2026-1733 is considered medium due to the potential for improper authorization vulnerabilities.
How do I fix CVE-2026-1733?
To fix CVE-2026-1733, update Zhong Bang CRMEB to version 5.6.4 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-1733?
CVE-2026-1733 is an improper authorization vulnerability affecting the tidyOrder function in Zhong Bang CRMEB.
Which versions of Zhong Bang CRMEB are affected by CVE-2026-1733?
Zhong Bang CRMEB versions up to and including 5.6.3 are affected by CVE-2026-1733.
What is the attack vector for CVE-2026-1733?
The attack vector for CVE-2026-1733 involves manipulating the order_id parameter in the API endpoint /api/store_integral/order/detail/:uni.