Data Exposure Risk in CordysCRM Open Source CRM System
CVE-2026-76901
5.8MEDIUM
What is CVE-2026-76901?
CordysCRM, an open source AI-powered customer relationship management system, is susceptible to a data exposure vulnerability. Prior to version 1.7.4, the application's GET endpoints in PoolClueController and PoolCustomerController utilize insufficient permission checks. This allows authenticated users with minimal permissions to access data belonging to other users, departments, or organizations by manipulating record IDs. Sensitive information, including contact names, phone numbers, and custom attributes, can be compromised. Users are encouraged to upgrade to version 1.7.4, which addresses these security concerns.
Affected Version(s)
CordysCRM < 1.7.4
