Missing Authorization Vulnerability in 1Panel-dev CordysCRM
CVE-2026-108701
Key Information:
- Vendor
1panel-dev
- Status
- Vendor
- CVE Published:
- 11 October 2026
Badges
What is CVE-2026-108701?
The CordysCRM application prior to version 1.9.2 is susceptible to a missing authorization vulnerability within its ContractController sortModule handler. This flaw allows authenticated users without the appropriate contract update permissions to manipulate any contract by supplying unauthorized parameters. As a result, these users can alter contracts belonging to other organizations, thereby posing a significant risk to data integrity and confidentiality. A fix for this vulnerability has been implemented in version 1.9.2.
Affected Version(s)
CordysCRM 0 < 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
