EIP-2026-112473

PRE-CVE

SugarCRM 6.5.18 - PHP Code Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112473. PoCs published by Egidio Romano.

AI-analyzed exploit summary The writeup describes two PHP code injection vulnerabilities in SugarCRM <= 6.5.18. The first involves improper escaping in the 'override_value_to_string_recursive2' function, allowing arbitrary PHP code execution via crafted input. The second allows authenticated administrators to upload and execute arbitrary PHP code through the Upgrade Wizard module.

Description

SugarCRM 6.5.18 - PHP Code Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by Egidio Romano · textwebappsphp
https://www.exploit-db.com/exploits/40027

The writeup describes two PHP code injection vulnerabilities in SugarCRM <= 6.5.18. The first involves improper escaping in the 'override_value_to_string_recursive2' function, allowing arbitrary PHP code execution via crafted input. The second allows authenticated administrators to upload and execute arbitrary PHP code through the Upgrade Wizard module.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SugarCRM <= 6.5.18
Auth required
Prerequisites: Network access to the target · For the second vulnerability, administrator credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026