CVE-2026-3265

MEDIUM

go2ismail free-crm < 2025-09-21 - Improper Authorization in Security API

Title source: llm
STIX 2.1

Description

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.347988
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.347988
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.758338

Scores

CVSS v3 6.3
EPSS 0.0046
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
go2ismail/free-crm < 2025-09-21
Published Feb 26, 2026
Tracked Since Feb 27, 2026