Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
Published: 2026-09-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to user event streams leading to information disclosure and potential service disruption
Action: Patch
AI Analysis

Impact

CordysCRM exposes its Server‑Sent Events API to the public. An attacker can supply any userId to the /sse/subscribe endpoint and receive that user’s workflow events, approval requests, mentions, and alerts. The API also allows unauthenticated users to send SYSTEM_HEARTBEAT messages via /sse/broadcast and to terminate other users’ channels with /sse/close. The missing authentication and improper user validation give the attacker read, write, and control capabilities over other users’ streams, resulting in confidentiality loss, UI manipulation, and potential denial of service. The weakness is a lack of authentication and authorization checks.

Affected Systems

The issue exists in the 1Panel‑dev CordysCRM distribution prior to version 1.7.2. Only that vendor and product are affected; the specific pre‑1.7.2 releases are vulnerable.

Risk and Exploitability

The CVSS score of 9.3 reflects critical severity, and the EPSS score is not available, but the vulnerability is trivially exploitable over the network because the endpoints are publicly accessible. An unauthenticated attacker can simply issue HTTP requests with a chosen userId to pull data or manipulate streams. The vulnerability is not listed in the CISA KEV catalog, yet the combination of high severity and ease of exploitation warrants immediate action. The likely attack vector is a conventional HTTP request to the public /sse/* endpoints, where the attacker supplies a userId to hijack another user’s stream.

Generated by OpenCVE AI on September 19, 2026 at 11:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CordysCRM to version 1.7.2 or later, which removes the unauthenticated access to the SSE endpoints.
  • If an upgrade is not immediately possible, reconfigure the ShiroFilter to reject all /sse/* requests from unauthenticated users and enforce authentication before any SSE interaction.
  • Validate that the SSE controller derives the channel’s user identity from the authenticated session and not from a caller‑supplied userId, ensuring that authorization checks are correctly performed.

Generated by OpenCVE AI on September 19, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared 1panel-dev
1panel-dev cordyscrm
Vendors & Products 1panel-dev
1panel-dev cordyscrm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
Title CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
Weaknesses CWE-306
CWE-639
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

1panel-dev Cordyscrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:19:30.108Z

Reserved: 2026-07-17T14:11:15.483Z

Link: CVE-2026-63647

cve-icon Vulnrichment

Updated: 2026-09-18T20:19:26.059Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:20.773

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-63647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-639

    Authorization Bypass Through User-Controlled Key