CordysCRM through 1.9.3 contains an authorization bypass vulnerability that allows low-privileged authenticated users to skip permission checks by setting the owner field to their own user id. Attackers can send requests to the follow/record/add endpoints to add follow-up records and overwrite follow_time and follower on any known customer, clue or opportunity.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 01:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:12:29.717Z
Reserved: 2026-10-10T23:08:48.380Z
Link: CVE-2026-108704
No data.
Status : Deferred
Published: 2026-10-11T02:16:38.980
Modified: 2026-10-11T02:16:39.107
Link: CVE-2026-108704
No data.
OpenCVE Enrichment
No data.
Weaknesses