Junglewise Threat Intelligence

CVE-2026-2141: WuKongOpenSource WukongCRM improper authorization in URL Handler

CVE-2026-2141 · Severity: medium · CVSS 6.3 · Published 2026-02-08

Technologies: 5kcrm Wukong Crm. Vendors: 5kcrm.

Executive brief

WukongCRM, an open-source customer relationship management platform, contains a security flaw that allows users to bypass authorization checks. An attacker can exploit this to view sensitive employee lists and reset any user's password, potentially leading to a full takeover of the CRM system. This could result in the theft of customer data and complete disruption of business operations.

Technical details

An improper authorization vulnerability (CWE-863/CWE-285) exists in WukongCRM up to version 11.3.3 within the PermissionServiceImpl.java component of the URL Handler. The flaw is a logical bypass that can be triggered by manipulating URL paths (e.g., using path traversal-like sequences such as '///;name=/v2/api-docs'). A remote attacker with low-level authenticated access can exploit this to perform unauthorized actions, specifically querying the full user list to obtain user IDs and subsequently resetting passwords for arbitrary accounts. While the vendor was notified, no official patch has been confirmed at the time of disclosure, and public exploits are available.

Affected products

  • WuKongOpenSource WukongCRM 11.0 through 11.3.3

Timeline

  • 2026-01-27: disclosed: Public issue report on GitHub with PoC details
  • 2026-02-08: advisory: NVD/VulDB publication

References

Related threats