Data Exposure Risk in CordysCRM Open Source CRM System
CVE-2026-76901

5.8MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-76901?

CordysCRM, an open source AI-powered customer relationship management system, is susceptible to a data exposure vulnerability. Prior to version 1.7.4, the application's GET endpoints in PoolClueController and PoolCustomerController utilize insufficient permission checks. This allows authenticated users with minimal permissions to access data belonging to other users, departments, or organizations by manipulating record IDs. Sensitive information, including contact names, phone numbers, and custom attributes, can be compromised. Users are encouraged to upgrade to version 1.7.4, which addresses these security concerns.

Affected Version(s)

CordysCRM < 1.7.4

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.