๐Ÿ” CVE Alert

CVE-2026-76901

MEDIUM 5.8

CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts

CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.get use bare pool-read permission checks without the CsPermission resourceId binding that enforces per-record data scope. An authenticated user with the ordinary CLUE_MANAGEMENT_POOL:READ or CUSTOMER_MANAGEMENT_POOL:READ permission can supply another record's id and cause unscoped primary-key getters to return leads or accounts owned by other users, departments, or organizations. Exposed data includes contact names, phone numbers, owner and department attribution, and custom field values. This issue is fixed in version 1.7.4.

CWE CWE-639
Vendor 1panel-dev
Product cordyscrm
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev cordyscrm

Be the first to know when new medium vulnerabilities affecting 1panel-dev cordyscrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

1Panel-dev / CordysCRM
< 1.7.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-hxp2-5w5p-2grq github.com: https://github.com/1Panel-dev/CordysCRM/pull/2976 github.com: https://github.com/1Panel-dev/CordysCRM/commit/34c7c3e5de2585208744926007530037a4ce4da5 github.com: https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.4