Junglewise Threat Intelligence

CVE-2026-16223: 1Panel-dev CordysCRM SSRF in Third Party Edit Endpoint

CVE-2026-16223 · Severity: medium · CVSS 6.3 · Published 2026-07-19

Technologies: 1Panel-dev CordysCRM, 1Panel-dev 1Panel. Vendors: 1Panel-dev.

Executive brief

1Panel-dev CordysCRM, an open-source AI-driven customer relationship management system, contains a security flaw in its third-party integration settings. An attacker with basic user permissions can trick the server into making unauthorized network requests to internal or external systems. This could allow an attacker to scan private internal networks, bypass firewalls, or potentially access sensitive data from other services within the corporate environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in 1Panel-dev CordysCRM up to version 1.4.1 within the IntegrationConfigService.java component. The application uses a regular expression to extract URLs from the 'appSecret' parameter in the /organization/settings/third-party/edit and /organization/settings/third-party/test endpoints. These extracted URLs are passed directly to URI.create().toURL().openConnection() without validation against a whitelist, protocol restrictions, or internal IP blocking. A remote attacker with SYSTEM_SETTING_READ or SYSTEM_SETTING_UPDATE permissions can exploit this to perform internal network reconnaissance or access internal services. The exploit has been publicly disclosed in GitHub issues #2687 and #2688.

Affected products

  • 1Panel-dev CordysCRM up to 1.4.1

Timeline

  • 2026-06-13: disclosed: Vulnerability details shared on GitHub issues 2687 and 2688
  • 2026-07-19: advisory: NVD/VulDB publication date

References

Related threats