CVE-2026-88467

Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

Published 2026-09-21. Last modified 2026-10-01.