CVE-2026-22356

HIGH

Jetpack CRM <=6.7.0 - PHP Local File Inclusion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-22356. PoCs published by xxconi.

AI-analyzed exploit summary The repository provides a technical analysis of CVE-2026-22356, detailing a path traversal vulnerability in Jetpack CRM leading to RCE via log poisoning. It includes a code snippet demonstrating the vulnerability and explains the patch applied in version 6.7.1.

Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.

Exploits (1)

github WRITEUP
by xxconi · poc
https://github.com/xxconi/CVE-2026-22356

The repository provides a technical analysis of CVE-2026-22356, detailing a path traversal vulnerability in Jetpack CRM leading to RCE via log poisoning. It includes a code snippet demonstrating the vulnerability and explains the patch applied in version 6.7.1.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Jetpack CRM (versions before 6.7.1)
No auth needed
Prerequisites: Access to a vulnerable Jetpack CRM instance · Ability to send crafted HTTP requests
devstral-2 · analyzed Jun 13, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 33.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-98
Status published
Products (2)
Automattic/Jetpack CRM < 6.7.0
Automattic/Jetpack CRM < <= 6.7.0
Published Feb 20, 2026
Tracked Since Feb 20, 2026