Missing Authorization in ChangeWeDer CRM's UserController Component
CVE-2026-92402

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92402?

A vulnerability has been identified in ChangeWeDer CRM, specifically in the UserController component's index function located in UserController.java, leading to missing authorization. This security flaw allows remote attackers to potentially exploit the system without proper authentication due to inadequate access controls. The issue was reported to the project, but a response has yet to be provided. As there is no versioning for the product, detailed information regarding affected and unaffected releases is currently unavailable.

Affected Version(s)

crm c07bd4c97141521af6475034bc58523beed51bbd

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mjh_123 (VulDB User)
VulDB CNA Team
.