Description
A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authentication leading to unauthorized access
Action: Monitor
AI Analysis

Impact

The vulnerability resides in the top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie function and allows an attacker to manipulate cookie data to bypass authentication. This improper authentication is a classic authorization flaw, classified as CWE-287, and grants unauthorized actors access to user accounts or restricted functions, compromising confidentiality and integrity of the system.

Affected Systems

Affected systems are the ChangeWeDer CRM product. No specific release numbers are provided; the issue exists in builds up to commit c07bd4c97141521af6475034bc58523beed51bbd. Because the project uses continuous delivery with rolling releases, any active deployment may be vulnerable until a fix is released.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability can be triggered remotely via crafted cookie data; no local or privileged access is required. The vulnerability is not listed in CISA KEV, so no immediate exploit evidence exists, but monitoring for suspicious authentication attempts remains prudent.

Generated by OpenCVE AI on September 18, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s official repository or issue tracker for a released fix and upgrade to the latest code version as soon as it is available.
  • Restrict or sanitize incoming cookie values, or disable cookie‑based authentication for critical actions until an official fix is implemented.
  • Deploy a web application firewall rule that flags or blocks requests containing malformed or unexpected cookie data.

Generated by OpenCVE AI on September 18, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title ChangeWeDer crm improper authentication
First Time appeared Changeweder
Changeweder crm
Weaknesses CWE-287
CPEs cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
Vendors & Products Changeweder
Changeweder crm
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T17:33:29.701Z

Reserved: 2026-09-16T08:50:50.212Z

Link: CVE-2026-92401

cve-icon Vulnrichment

Updated: 2026-09-16T17:33:26.314Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:19.773

Modified: 2026-09-16T18:17:19.743

Link: CVE-2026-92401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses