CVE-2026-85040 | ZhongBangKeJi CRMEB up to 6.0.0 Custom Scheduled Task Feature save eval customCode os command injection

SecurityVulns

A vulnerability classified as problematic has been found in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the component Custom Scheduled Task Feature. This manipulation of the argument customCode causes os command injection.

The identification of this vulnerability is CVE-2026-85040. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Vendor documents this as deliberate debug-only behavior. But isSafePhpCode blacklist offers no real RCE containment.VulDB Recent EntriesRead More