CVE-2026-3265

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Ghufran2/CVE-Free-CRM-Advisories/blob/main/Free-CRM%20IDOR.md Exploit Mitigation Third Party Advisory
https://vuldb.com/?ctiid.347988 Permissions Required VDB Entry
https://vuldb.com/?id.347988 Third Party Advisory VDB Entry
https://vuldb.com/?submit.758338 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:go2ismail:free-crm:*:*:*:*:*:*:*:*

History

03 Mar 2026, 19:47

Type Values Removed Values Added
References () https://github.com/Ghufran2/CVE-Free-CRM-Advisories/blob/main/Free-CRM%20IDOR.md - () https://github.com/Ghufran2/CVE-Free-CRM-Advisories/blob/main/Free-CRM%20IDOR.md - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.347988 - () https://vuldb.com/?ctiid.347988 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347988 - () https://vuldb.com/?id.347988 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758338 - () https://vuldb.com/?submit.758338 - Third Party Advisory, VDB Entry
First Time Go2ismail
Go2ismail free-crm
CPE cpe:2.3:a:go2ismail:free-crm:*:*:*:*:*:*:*:*

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en go2ismail Free-CRM hasta b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Esto afecta una parte desconocida del archivo /api/Security/ del componente Security API. La manipulación conduce a una autorización indebida. El ataque es posible de llevar a cabo remotamente. El exploit está disponible públicamente y podría ser utilizado. Este producto adopta una estrategia de lanzamiento continuo para mantener la entrega continua. Por lo tanto, los detalles de la versión para las versiones afectadas o actualizadas no pueden especificarse. El proveedor fue contactado con antelación sobre esta divulgación, pero no respondió de ninguna manera.

26 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 23:16

Updated : 2026-03-03 19:47


NVD link : CVE-2026-3265

Mitre link : CVE-2026-3265

CVE.ORG link : CVE-2026-3265


JSON object : View

Products Affected

go2ismail

  • free-crm
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization