Improper authentication vulnerability in ChangeWeDer CRM
CVE-2026-92401

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92401?

An improper authentication vulnerability has been discovered in ChangeWeDer CRM, particularly affecting the function responsible for managing user sessions. This flaw could allow attackers to bypass authentication mechanisms remotely, potentially compromising user accounts and leading to unauthorized access. The software uses a continuous delivery model with rolling releases, which complicates version tracking for users. Despite initial reports of the vulnerability to the vendor, there has been no acknowledgment or remediation at this time. It is crucial for users of ChangeWeDer CRM to remain vigilant and take appropriate security measures.

Affected Version(s)

crm c07bd4c97141521af6475034bc58523beed51bbd

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mjh_123 (VulDB User)
VulDB CNA Team
.