Impact
The vulnerability is an insecure deserialization flaw in the Pivotal.Engine.Client.Services.Conversion.dll component from an incomplete fix of a previous CVE. A remote attacker can craft malicious payloads that are deserialized and executed as arbitrary code, a weakness classified as CWE-502.
Affected Systems
Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip that have not applied the fix remain vulnerable. The flaw is resolved in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip.
Risk and Exploitability
The flaw is an insecure deserialization vulnerability in the Pivotal.Engine.Client.Services.Conversion.dll component that originates from an incomplete remediation of CVE-2026-39253. A remote attacker can send a crafted payload over the network to the Pivotal CRM application, which is then deserialized by the vulnerable component, resulting in arbitrary code execution on the host. The CVSS score of 9.8 highlights the severity of this issue, and the EPSS value of 1 % indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and the remote attack surface keep the overall risk elevated.
OpenCVE Enrichment