CVE-2026-7673: crmeb_java Admin Upload UploadServiceImpl.java unrestricted upload
A vulnerability was detected in crmebjava up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7673?
CVE-2026-7673 has been classified with a potentially high severity due to its unrestricted file upload vulnerability.
How do I fix CVE-2026-7673?
To fix CVE-2026-7673, upgrade to the latest version of crmeb_java beyond 1.3.4 to apply the necessary security patches.
What component is affected by CVE-2026-7673?
CVE-2026-7673 affects the UploadServiceImpl.java file within the Admin Upload component of crmeb_java.
What types of attacks could CVE-2026-7673 facilitate?
CVE-2026-7673 could facilitate attacks such as remote code execution due to unrestricted file uploads.
Is there a known exploit for CVE-2026-7673?
As of now, there are no publicly known exploits specifically targeting CVE-2026-7673, but the risk remains significant without mitigation.