Back

HIGH

Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module

Published Jul 7, 2026

Description

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 7, 2026
Updated Jul 14, 2026
Reserved Jan 14, 2026
CISA Vulnrichment
Updated Jul 7, 2026
NVD
Status Deferred
Modified Jul 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Jul 7, 2026
Updated Jul 14, 2026
Exploited since n/a
EUVD-2026-42055