
CVE-2025-67886 Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sendin… https://www.cve.org/CVERecord?id=CVE-2025-67886
Post summary
The excerpt announces CVE-2025-67886, a Remote Code Execution flaw in Bitrix24 up to 25.100.300, where users with SOURCE/WRITE permissions on the Translate Module can upload and execute code.
