Exposed Endpoints in CordysCRM Allow Unauthorized Access to User Data
CVE-2026-63647

9.3CRITICAL

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-63647?

CordysCRM, an open-source AI-powered customer relationship management system, has a vulnerability due to improperly secured server-sent event (SSE) endpoints. The anonymous endpoints /sse/subscribe, /sse/broadcast, and /sse/close are accessible to unauthenticated users, allowing them to interact with another user's workflow events, approval requests, and alerts. Furthermore, attackers can inject SYSTEM_HEARTBEAT messages into a user's stream or terminate their connection. This security flaw arises from the ShiroFilter permitting public access to the sensitive SSE paths without verifying user identity against authenticated principals. It has been addressed in version 1.7.2.

Affected Version(s)

CordysCRM < 1.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.