CVE-2026-66028
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-303
- Published
- 2026-07-27
- Last modified
- 2026-07-28
Affected products
- Creativeitem Ekushey Project Manager CRM
Weakness type
Related vulnerabilities
- CVE-2026-78629 — Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
- CVE-2026-9854 — A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools...
- CVE-2026-9853 — A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the...
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-66411 — DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket...
- CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-59309 — vCenter authentication-bypass vulnerability