CVE-2026-79426 Details
Description
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.
A vulnerability allowing authenticated attackers to delete arbitrary files has been identified in CRMEB version 6.0.0. This issue arises in the '/adminapi/file/video_data_save' component, where the application fails to properly validate file paths before deletion. Attackers with administrator privileges and file-management rights can exploit this vulnerability by sending crafted POST requests that include paths to files they wish to delete. The vulnerability is present when local storage is enabled, as it allows the deletion of files accessible to the PHP process, potentially leading to application disruption, data loss, or a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-79426.md | CISA-ADP | AdvisoryExploitRemedy |
| https://github.com/crmeb/CRMEB | [email protected] | ProductSource CodeVendor |
| https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-79426.md | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| CRMEB | 6.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion