Bitrix24 Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Bitrix24, allowing authenticated users to execute arbitrary system commands via the PHP command line administration interface. This vulnerability arises from missing authorization checks, enabling logged-in attackers to send crafted POST requests to the administrative endpoint and execute commands with the privileges of the web application.

Impact

Exploitation of this vulnerability allows for authenticated remote code execution on the server where Bitrix24 is hosted.

Reproduction

To reproduce this vulnerability, log into Bitrix24 and navigate to the administrative PHP command line interface. Once there, send a POST request containing the desired system command to be executed. The command will be executed with the privileges of the web application, and the result can be retrieved from the command line interface.

Added: Jan 14, 2026, 12:25 AM
Updated: Jan 14, 2026, 12:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
10.0
exploitability
6.6
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.