Vulnerability Description
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Znuny | Znuny | >= 6.0.31, <= 6.0.48 |
Related Weaknesses (CWE)
References
- https://www.znuny.comProduct
- https://www.znuny.org/en/advisories/zsa-2025-03Vendor Advisory
FAQ
What is CVE-2025-26845?
CVE-2025-26845 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
How severe is CVE-2025-26845?
CVE-2025-26845 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-26845?
Check the references section above for vendor advisories and patch information. Affected products include: Znuny Znuny.