Authorization Flaw in yshop-crm Affects Customer Management Policies
CVE-2026-92456

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-92456?

The yshop-crm product version 2.1.3 contains an authorization vulnerability that permits any authenticated back-office user to access and alter critical settings through the saveRedisSet and getRedisSet endpoints in the CrmCustomerController. This flaw allows users to manipulate shared Redis keys governing customer auto-recycling and lead allocation policies, which could lead to unintended customer data deletion or interruptions in customer creation processes. The absence of proper access controls could expose sensitive configuration aspects to unauthorized modifications, significantly threatening the integrity and functionality of customer management operations.

Affected Version(s)

yshop-crm 0 <= 2.1.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingsheng Lin (lincoke)
.