Junglewise Threat Intelligence

CVE-2026-10282: Bottelet DaybydayCRM improper authorization in DocumentsController

CVE-2026-10282 · Severity: medium · CVSS 4.3 · Published 2026-06-01

Executive brief

Bottelet DaybydayCRM, an open-source customer relationship management platform, contains a security flaw that allows logged-in users to access documents they do not own. By manipulating document identifiers, an attacker could view or download sensitive files associated with other clients, tasks, or projects. This could lead to the unauthorized exposure of confidential business information and customer data.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Bottelet DaybydayCRM up to 2.2.1 within the `view` and `download` methods of `app/Http/Controllers/DocumentsController.php`. The application fails to perform ownership or permission checks when retrieving documents via their `external_id`, allowing any authenticated user to access files by guessing or obtaining the identifier. Additionally, missing permission checks were identified in the `updateAssign` methods of the Tasks, Projects, and Leads controllers. An attacker with low-privileged network access can exploit this to bypass intended access controls. A patch has been developed to implement proper authorization gates and ownership validation.

Affected products

  • Bottelet DaybydayCRM up to 2.2.1

Timeline

  • 2026-02-25: disclosed: Vulnerability reported via GitHub issue #347
  • 2026-04-08: patched: Fix merged in pull request #362
  • 2026-06-01: advisory: CVE-2026-10282 published

References

Related threats