Authorization Flaw in CordysCRM Affects File Access Controls
CVE-2026-76902

5MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-76902?

CordysCRM, an open source AI-powered customer relationship management system, is affected by a vulnerability that allows unauthenticated users to access files belonging to other organizations. This issue arises from the improper configuration of the ShiroFilter for routes that preview attachments. Specifically, prior to version 1.7.4, the methods for previewing attachments did not properly enforce ownership or permission checks, allowing an attacker to exploit predictable resource identifiers to access unauthorized files. This security flaw was resolved in version 1.7.4.

Affected Version(s)

CordysCRM < 1.7.4

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.