Authorization Flaw in CordysCRM Affects File Access Controls
CVE-2026-76902
5MEDIUM
What is CVE-2026-76902?
CordysCRM, an open source AI-powered customer relationship management system, is affected by a vulnerability that allows unauthenticated users to access files belonging to other organizations. This issue arises from the improper configuration of the ShiroFilter for routes that preview attachments. Specifically, prior to version 1.7.4, the methods for previewing attachments did not properly enforce ownership or permission checks, allowing an attacker to exploit predictable resource identifiers to access unauthorized files. This security flaw was resolved in version 1.7.4.
Affected Version(s)
CordysCRM < 1.7.4
