Authentication Bypass in CordysCRM Affects User Data Security
CVE-2026-63646
6.9MEDIUM
What is CVE-2026-63646?
CordysCRM, an open-source AI-driven customer relationship management system, has a critical authentication bypass vulnerability. Prior to version 1.7.2, the system's GET request for form configurations could be accessed without authentication due to improper security configurations. Specifically, the McpController.getMcpField method allows unauthenticated users to retrieve sensitive information such as field names, types, validation rules, and binding sources necessary for CRM modules. This exposure can lead to targeted attacks, enabling attackers to reconstruct application data models and exploit additional vulnerabilities. Upgrade to version 1.7.2 to secure your instance against these issues.
Affected Version(s)
CordysCRM < 1.7.2
