Back to overview

CVE-2026-66028

MEDIUM Exploitation: PoC
6.7
CVSS 3.1
Description
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.

Metadata

CVE ID
CVE-2026-66028
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-23 20:45 UTC
Published
2026-07-27 18:00 UTC
Last updated
2026-07-28 01:06 UTC
Primary CWE
CWE-303
Incorrect Implementation of Authentication Algorithm
Vendor / Product
Creativeitem / Ekushey Project Manager CRM
Sources
cve.org  ·  NVD

Severity & Metrics

6.7 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Creativeitem Ekushey Project Manager CRM 0 ≤ 5.0
Weakness (CWE)
CWESourceDescription
CWE-303 cna Incorrect Implementation of Authentication Algorithm
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
6.7 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Back to overview