CVE-2026-66028
Last modified
CVE-2026-66028 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Creativeitem | Ekushey Project Manager CRM | <= 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66028?
How severe is CVE-2026-66028?
How do I fix CVE-2026-66028?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66014JFrog Artifactory contains an authentication handling weakne…9.8
- CVE-2026-66015An authenticated privilege-escalation vulnerability in JFrog…7.2
- CVE-2026-66016Under specific self-hosted Helm configurations, generated TL…6.7
- CVE-2026-66018Build readers can access another repository's environment pr…6.5
- CVE-2026-6602A vulnerability was found in rickxy Hospital Management Syst…7.3
- CVE-2026-66027Suna before 0.9.102 contains a broken access control vulnera…8.7
- CVE-2026-66029Ekushey Project Manager CRM through version 5.0 contains a s…5.4
- CVE-2026-6603A vulnerability was determined in modelscope agentscope up t…7.3
- CVE-2026-66030Ekushey Project Manager CRM through version 5.0 ccontains a …5.4
- CVE-2026-66031Ekushey Project Manager CRM through version 5.0 contains a s…5.4
- CVE-2026-66032libssh2 through 1.11.1, fixed in commit 5e47761, contains a …8.8
- CVE-2026-66033libssh2 through 1.11.1, fixed in commit a2ed82d, contains a …8.7
Are you affected by CVE-2026-66028?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
