Description
A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The manipulation results in missing authorization. The attack can be launched remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Missing Authorization
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises from a missing authorization check in the index function of UserController.java, allowing an attacker to invoke the endpoint without proper privileges. This weakness permits unauthenticated or improperly authenticated users to access or manipulate resources that should be protected, representing missing authorization and missing access control errors (CWE-862, CWE-863). The flaw could enable attackers to read sensitive data or perform operations beyond intended permissions.

Affected Systems

The flaw affects the ChangeWeDer CRM application (product ChangeWeDer:crm). All deployed instances built with code at or before commit c07bd4c97141521af6475034bc58523beed51bbd are considered vulnerable because the project does not use versioning and the official fix has not been released. Therefore, any version of the application that has not yet incorporated the remediation is potentially impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, while the EPSS score below 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw remotely by calling the vulnerable index endpoint, potentially bypassing authentication checks. The lack of explicit authentication prerequisites in the public description implies that the flaw could be exploited regardless of user credentials, making the risk moderate but unlikely to be widely observed today.

Generated by OpenCVE AI on September 18, 2026 at 05:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch or update to a version that resolves the missing authorization in UserController's index method.
  • Implement network-level filtering to restrict access to the /index endpoint or the CRM application to trusted IP addresses or authenticated users.
  • Review and reinforce application-level access control rules, ensuring that the index operation is protected by appropriate authentication and authorization checks.
  • Monitor application logs for unexpected access to the index endpoint and investigate any unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The manipulation results in missing authorization. The attack can be launched remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization
First Time appeared Changeweder
Changeweder crm
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
Vendors & Products Changeweder
Changeweder crm
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:45:29.315Z

Reserved: 2026-09-16T08:50:54.007Z

Link: CVE-2026-92402

cve-icon Vulnrichment

Updated: 2026-09-22T15:06:24.051Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:19.950

Modified: 2026-09-22T16:18:11.713

Link: CVE-2026-92402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses