CVE-2026-33733

Source
https://cve.org/CVERecord?id=CVE-2026-33733
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33733.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33733
Aliases
  • GHSA-44c3-xjfp-3jrh
Published
2026-04-22T20:05:23.809Z
Modified
2026-07-15T01:49:04.749334671Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete
Details

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. As a result, an authenticated admin can use ../ sequences to escape the intended template directory and read, create, overwrite, or delete arbitrary files that resolve to body.tpl or subject.tpl under the web application user's filesystem permissions. Version 9.3.4 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-23"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33733.json"
}
References

Affected packages

Git / github.com/espocrm/espocrm

Affected ranges

Type
GIT
Repo
https://github.com/espocrm/espocrm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "9.3.4"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
2.*
2.0.1
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.8.0
2.8.1
2.9.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.5.0
3.6.0
3.6.1
3.7.0
3.7.1
3.8.0
3.9.0
3.9.1
4.*
4.0.0
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-beta.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.0-beta.1
4.3.0-beta.2
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.3.0
5.3.1
5.3.2
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.6.0
5.6.1
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.7.5
5.8.0
5.8.1
5.8.2
5.9.0
5.9.1
5.9.2
6.*
6.0.0
6.0.0-beta1
6.0.0-beta2
6.0.0-beta4
6.0.1
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.1
7.1.2
7.1.3
7.2.0
7.3.0
7.4.0
7.4.1
7.4.2
7.4.3
8.*
8.0.0
8.0.1
8.0.2
8.1.0
8.2.0
8.4.0
9.*
9.0.0
9.0.1
9.0.2
9.1.0
9.2.0
9.3.0
9.3.1
9.3.2
9.3.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33733.json"