SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79426

HIGH · CVSS 7.2 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An arbitrary file deletion vulnerability exists in the /adminapi/file/video_data_save component of CRMEB v6.0.0, enabling authenticated attackers to delete any file by sending a specially crafted POST request. This flaw could lead to significant data loss and potential disruption of services. Organizations using this version of CRMEB should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79426
Severity
HIGH
CVSS
7.2
EPSS
0.29%

Original NVD Description

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.