logo

From Discovery to Disclosure: ReCrystallize Server Vulnerabilities

ID: 0411d22f-7e51-5861-a3fb-59013f9016de

STIX ID: report--0411d22f-7e51-5861-a3fb-59013f9016de

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2024-03-22

Date Updated: 2026-04-30

...
...

This blog post describes the discovery and responsible disclosure of multiple vulnerabilities in ReCrystallize Server — notably an authentication bypass (CVE-2024-26331) and an unrestricted file upload that enables remote code execution (CVE-2024-28269). The author demonstrates exploitation (including RCE as SYSTEM and outbound SMB/NTLM capture), details additional insecure features (unauthenticated file download, LFI-like behavior), and provides mitigation guidance and a disclosure timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.