Bitrix24 contains an authenticated remote code execution vulnerability that allows logged-in attackers to execute arbitrary system commands through the PHP command line admin interface. Attackers can leverage the vulnerability by sending crafted POST requests to the administrative endpoint with system commands to execute code with the web application's privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bitrix24 contains an authenticated remote code execution vulnerability that allows logged-in attackers to execute arbitrary system commands through the PHP command line admin interface. Attackers can leverage the vulnerability by sending crafted POST requests to the administrative endpoint with system commands to execute code with the web application's privileges. | |
| Title | Bitrix24 - Remote Code Execution (RCE) (Authenticated) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:51:50.943Z
Reserved: 2026-01-11T13:14:18.876Z
Link: CVE-2022-50911
No data.
Status : Received
Published: 2026-01-13T23:15:54.173
Modified: 2026-01-13T23:15:54.173
Link: CVE-2022-50911
No data.
OpenCVE Enrichment
No data.