SSRF Vulnerability in CordysCRM Affects Internal Network Security
CVE-2026-76900
6.8MEDIUM
What is CVE-2026-76900?
In CordysCRM version 1.7.3, a vulnerability in the ApprovalResourceService allows a user with PROCESS_SETTING_ADD permissions to configure an internal URL. This setup can lead to an unvalidated request being initiated towards internal resources through the ApprovalFlowService, granting access to sensitive cloud metadata and enabling reconnaissance of internal networks. This flaw is remediated in version 1.7.4, which includes necessary SSRF validations to mitigate such risks.
Affected Version(s)
CordysCRM = 1.7.3
