SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-50769

CRITICAL · CVSS 9.8 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The CRM+ application, up to version 2025.6, is susceptible to a time-based SQL Injection vulnerability in the check conflict endpoint, which could allow attackers to execute arbitrary code. This poses a significant risk to the integrity and confidentiality of user data, making it critical for organizations using this application to prioritize remediation efforts. Users of the affected CRM+ version should urgently assess their exposure and implement necessary security measures.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50769
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%

Original NVD Description

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.