Junglewise Threat Intelligence

CVE-2026-76901: CordysCRM authorization bypass in pool lead and account retrieval

CVE-2026-76901 · Severity: medium · CVSS 5.8 · Published 2026-09-18

Technologies: 1Panel-dev CordysCRM. Vendors: 1Panel-dev.

Executive brief

CordysCRM is an open source customer relationship management system. Versions before 1.7.4 allow authenticated users with basic read permissions to retrieve leads and accounts belonging to other users, departments, or organizations by directly querying record IDs. An attacker can expose contact information, phone numbers, and custom field data without proper access controls.

Technical details

The vulnerability is an authorization bypass in GET /pool/lead/get/{id} and GET /pool/account/get/{id} endpoints within PoolClueController and PoolCustomerController. These endpoints perform only bare permission checks (CLUE_MANAGEMENT_POOL:READ, CUSTOMER_MANAGEMENT_POOL:READ) without resource-scoped authorization, allowing any authenticated user with these permissions to enumerate and retrieve records by ID. The fix adds checkPoolMember validation to enforce per-record data scope.

Affected products

  • 1Panel-dev CordysCRM before 1.7.4

Timeline

  • 2026-09-18: disclosed
  • 2026-07-09: patched: fix merged in commit 34c7c3e

References

Related threats