What is CVE-2026-66028?
Ekushey Project Manager CRM up to version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit this lack of email field uniqueness enforcement to manipulate account creation. Affected systems should be updated to the latest version immediately.
Azərbaycanca: Ekushey Project Manager CRM-in 5.0 versiyasına qədər olan versiyalarında autentifikasiya olunmuş administratorlara eyni e-poçt və parolla dublikat müştəri hesabları yaratmağa imkan verən unikallıq məhdudiyyətinin olmaması zəifliyi aşkarlanıb. Bu, təcavüzkarlara hesab yaratma mexanizmini manipulyasiya etməyə şərait yaradır. Təsirə məruz qalan sistemlərin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
FAQ2
Which versions of Ekushey Project Manager CRM are affected by CVE-2026-66028?
This vulnerability affects Ekushey Project Manager CRM up to version 5.0.
How can an authenticated administrator exploit this vulnerability?
Authenticated administrators can create duplicate client accounts with identical email and password combinations because the email field lacks a uniqueness constraint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.