CVE-2025-67886

medium

Description

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.

References

https://seclists.org/fulldisclosure/2025/Dec/21

https://www.bitrix24.com/self-hosted/

https://karmainsecurity.com/pocs/CVE-2025-67886.php

https://dev.1c-bitrix.ru/learning/course/?COURSE_ID=43&LESSON_ID=3055

https://dev.1c-bitrix.ru/api_help/translate/index.php

http://seclists.org/fulldisclosure/2025/Dec/21

Details

Source: Mitre, NVD

Published: 2026-05-08

Updated: 2026-05-08

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00023