SSRF Vulnerability in CordysCRM Affects Internal Network Security
CVE-2026-76900

6.8MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-76900?

In CordysCRM version 1.7.3, a vulnerability in the ApprovalResourceService allows a user with PROCESS_SETTING_ADD permissions to configure an internal URL. This setup can lead to an unvalidated request being initiated towards internal resources through the ApprovalFlowService, granting access to sensitive cloud metadata and enabling reconnaissance of internal networks. This flaw is remediated in version 1.7.4, which includes necessary SSRF validations to mitigate such risks.

Affected Version(s)

CordysCRM = 1.7.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.