Authorization Flaw in yshop-crm Affects Customer Management Policies
CVE-2026-92456
Key Information:
- Vendor
Guchengwuyue
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-92456?
The yshop-crm product version 2.1.3 contains an authorization vulnerability that permits any authenticated back-office user to access and alter critical settings through the saveRedisSet and getRedisSet endpoints in the CrmCustomerController. This flaw allows users to manipulate shared Redis keys governing customer auto-recycling and lead allocation policies, which could lead to unintended customer data deletion or interruptions in customer creation processes. The absence of proper access controls could expose sensitive configuration aspects to unauthorized modifications, significantly threatening the integrity and functionality of customer management operations.
Affected Version(s)
yshop-crm 0 <= 2.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
