Junglewise Threat Intelligence

CVE-2026-76902: CordysCRM unauthenticated file download in attachment preview

CVE-2026-76902 · Severity: medium · CVSS 5 · Published 2026-09-18

Vendors: 1Panel.

Executive brief

CordysCRM is an open-source AI-powered customer relationship management system. The file preview endpoints allow unauthenticated access and perform no authorization checks, enabling attackers to download files uploaded by users in other organizations by guessing file identifiers. This could expose sensitive business data across organizations.

Technical details

The /attachment/preview/{id} and /pic/preview/{id} endpoints are configured as anonymous in ShiroFilter and call AttachmentService.getResource, which performs only a bare primary-key lookup without checking ownership, organization membership, or permissions. An attacker can predict or discover file IDs (generated by IDGenerator.nextStr) and retrieve files belonging to other organizations. The fix in version 1.7.4 introduces a FileAccessAuthFilter to enforce proper authorization.

Affected products

  • 1Panel CordysCRM prior to 1.7.4

Timeline

  • 2026-09-18: disclosed
  • 2026-07-10: patched: Fix released in version 1.7.4

References

Related threats