https://reddit.com/r/netsec/comments/1s39ujn/cve202633656_espocrm_933_formula_engine_acl_gap/: CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC)
Published Mar 25, 2026
·Updated
Affected Software
1 affected component
EspoCRM EspoCRM<=9.3.3
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires administrator credentials. The described attack chain uses the formula engine to modify a field that is otherwise marked read-only.
2
Which deployments are affected?
EspoCRM versions through 9.3.3 are affected according to the provided information. Version 9.3.4 contains the coordinated-disclosure patch.
3
What access does successful exploitation provide?
The described chain results in remote code execution as the www-data user. It uses path manipulation through Attachment.sourceId, a chunked upload, and .htaccess poisoning.