CVE-2026-7673Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-03: 4Technical Details · 2026-05-03: 205-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7673 📊 Severity: 4.7 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7673 #CVE-2026-7673 #CVE #Medium #CyberSecurity #InfoSec https://t.co/3XRuxuPr8b

    Post summary

    The tweet announces the disclosure of CVE-2026-7673, notes its medium severity, and references the NVD entry, but provides no deeper technical or exploitation information.

    0000048
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7673 A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/i… https://www.cve.org/CVERecord?id=CVE-2026-7673 ----- Traducción: CVE-2026-7673 Se … http://infoflow.cloud`

    Post summary

    The post announces detection of CVE‑2026‑7673 in the crmeb_java application, specifying affected version and component but providing no PoC, exploit, or mitigation details.

    0000027
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7673 A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/i… https://www.cve.org/CVERecord?id=CVE-2026-7673

    Post summary

    A CVE has been reported for crmeb_java, but no detailed technical information, PoC, active exploitation, or patch guidance is provided.

    00000254
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7673 Unrestricted File Upload Vulnerability in CRMEB Java Up To 1.3.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7673 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    This brief alert announces CVE-2026-7673 as an unrestricted file upload flaw in CRMEB Java versions up to 1.3.4, providing a link for further details but offering no PoC, exploit code, active exploitation evidence, or patch information.

    0000044
    4.0K followersView on X

Explore more