CVE-2026-33656Disclosure(espocrm / espocrm)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for espocrm espocrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Attachment` entities. Because `sourceId` is concatenated directly into a file path with no sanitization in `EspoUploadDir::getFilePath()`, an attacker can redirect any file read or write operation to an arbitrary path within the web server's `open_basedir` scope. Version 9.3.4 fixes the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • espocrm

Threat summary

  • Public PoC and exploit tooling are both present
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 3 mentions (2026-03-25); latest day: 2
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
espocrm

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-29: 1Mentions · 2026-03-31: 1Mentions · 2026-04-04: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 2PoC Mentioned / Linked · 2026-03-25: 2PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-03-31: 1Exploit Tool / Code · 2026-03-31: 1Technical Details · 2026-03-25: 3Technical Details · 2026-03-29: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 103-2503-2903-3104-0404-2204-23
Signal classification3 categories
Disclosure
444.4%
PoC
444.4%
General
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-253
Disclosure1PoC2
2026-03-291
PoC1
2026-03-311
PoC1
2026-04-041
Disclosure1
2026-04-221
Disclosure1
2026-04-232
Disclosure1General1
Full discourse9 posts
  • /r/netsec@_r_netsec
    PoC

    CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC) https://jivasecurity.com/writeups/espocrm-rce-cve-2026-33656

    Post summary

    The post announces CVE‑2026‑33656 in EspoCRM, detailing an ACL gap and path traversal that enable authenticated RCE, and links to a full write‑up with a proof‑of‑concept.

    03031598
    32.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33656 EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachme… https://www.cve.org/CVERecord?id=CVE-2026-33656

    Post summary

    The post identifies CVE-2026-33656 in EspoCRM but offers no additional details about the vulnerability, its exploitation, or remediation.

    00010101
    57.2K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #EspoCRM. CVE-2026-33656 CVSS: 9.1. This vulnerability is only exploitable by an admin user and can lead to remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    This tweet announces a severe CVE‑2026‑33656 in EspoCRM that enables remote code execution for admin users, but it lacks information on patches, PoC, or active exploitation.

    01000175
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33656: EspoCRM vulnerable to authentica... Admin-level path traversal in EspoCRM's formula engine bypasses all sanitization—concatenated `sourceId` = instant webs... https://zerodaysignal.com/vulnerability/CVE-2026-33656 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new EspoCRM path traversal vulnerability (CVE‑2026‑33656), describing how an admin‑level traversal bypasses sanitization. No evidence of active exploitation or available patches is mentioned.

    00000109
    218 followersView on X
  • CompuChris@compuchris
    Disclosure

    CVE-2026-33656: EspoCRM ≤ 9.3.3 — Authenticated RCE via path traversal + formula engine (CVSS 9.1 Critical, full write-up) #CISO https://www.reddit.com/r/cybersecurity/comments/1s46e16/cve202633656_espocrm_933_authenticated_rce_via/

    Post summary

    The tweet announces CVE‑2026‑33656, a critical (CVSS 9.1) authenticated RCE in EspoCRM versions ≤ 9.3.3 via path traversal and the formula engine, but does not mention active exploitation, a PoC, an exploit tool, or mitigation information.

    0000052
    1.7K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    EspoCRM 9.3.3 contains a critical RCE flaw (CVE-2026-33656). Learn how the "Formula Engine" can be weaponized to seize server control in just six requests. #EspoCRM #CyberSecurity2026 #RCE #CVE202633656 #Infosec #BugBounty #ServerSecurity #Exploit https://meterpreter.org/six-clicks-to-root-how-espocrms-formula-engine-became-a-gateway-for-server-takeover/ https://t.co/kbxj1SUiWM

    Post summary

    EspoCRM 9.3.3’s Formula Engine contains a critical RCE (CVE‑2026‑33656) that can be exploited in just six requests, with a PoC publicly referenced. No evidence of active exploitation or patched mitigations is provided.

    00000288
    11.0K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    PoC

    CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC) https://www.reddit.com/r/netsec/comments/1s39ujn/cve202633656_espocrm_933_formula_engine_acl_gap/

    Post summary

    The post announces CVE-2026-33656, detailing an authenticated RCE via a formula‑engine ACL gap and path traversal in EspoCRM ≤9.3.3, and shares a full write‑up and PoC.

    0000068
    237 followersView on X
  • Security Harvester@secharvesterx
    PoC

    CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC) https://jivasecurity.com/writeups/espocrm-rce-cve-2026-33656 https://t.co/CxNGHSjCGi

    Post summary

    EspoCRM ≤ 9.3.3 is vulnerable to authenticated RCE via a formula engine ACL gap coupled with path traversal. A complete write‑up and PoC are available.

    00000107
    808 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33656 EspoCRM <= 9.3.3 CVE-2026-33656 — Authenticated RCE via Formula ACL Bypass + Attachment sourceId Path Traversal + .htaccess Poisoning Author https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33656

    Post summary

    The text announces CVE-2026-33656, detailing authenticated RCE through Formula ACL bypass, path traversal with attachment sourceId, and .htaccess poisoning, and directs readers to a vulnerability details page.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appespocrmespocrm---

Explore more