CVE-2026-51947 Details
Description
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix for CVE-2026-39253.
A vulnerability in Pivotal CRM versions 6.6.4.08 and those using the patch 'patch-ghi-15381-cwe-502-20251225.zip' allows remote code execution through the 'Pivotal.Engine.Client.Services.Conversion.dll' component. This issue arises from an insecure deserialization flaw that was not fully addressed in a previous patch for CVE-2026-39253. The vulnerability can be exploited by crafting a malicious JSON payload that takes advantage of the deserialization process, bypassing security controls and executing arbitrary commands.
Users can upgrade to Pivotal CRM 6.6.5.10, which includes the complete fix for this vulnerability. For those unable to upgrade immediately, a standalone patch 'Patch_CWE502_20260316.zip' is available and can be applied to both the Pivotal Smart Client and Pivotal Business Server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |