SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66028

MEDIUM · CVSS 6.7 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Ekushey Project Manager CRM versions prior to 5.0 are vulnerable due to a missing uniqueness constraint that permits authenticated administrators to create duplicate client accounts with the same email and password. This flaw can lead to unpredictable authentication behavior and unauthorized access, as conflicting accounts can exist with identical email addresses but different passwords. Organizations using this CRM should prioritize remediation to prevent potential exploitation by malicious actors.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66028
Severity
MEDIUM
CVSS
6.7
EPSS
0.32%

Original NVD Description

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.