CVE-2026-108701
Deferred Deferred - Pending Action

Missing Authorization in 1Panel-dev CordysCRM Contract Sort

Vulnerability report for CVE-2026-108701, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule handler for POST /contract/sort, which lacks any permission annotation. Authenticated users without contract update permission can supply a dragNodeId, stage and field values to modify any contract, including contracts in other organizations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
1Panel-dev CordysCRM 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108701 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions before 1.9.2. The flaw exists in the ContractController's sortModule handler for the POST /contract/sort endpoint. Authenticated users without contract update permissions can exploit this by providing dragNodeId, stage, and field parameters to modify any contract, including those in other organizations.

Detection Guidance

To detect this vulnerability, monitor POST requests to /contract/sort endpoints in CordysCRM. Check for unauthenticated or unauthorized users attempting to modify contract stages, positions, or fields. Review logs for suspicious dragNodeId, stage, or field parameter values being submitted by non-admin users.

Impact Analysis

An attacker with authenticated access could modify contracts they shouldn't have permission to change. This includes altering contract stages, positions, or fields, potentially leading to unauthorized data changes, contract manipulation, or organizational data breaches.

Compliance Impact

This vulnerability could lead to unauthorized data modifications, violating integrity and access control requirements in GDPR and HIPAA. It may result in non-compliance with data protection principles, potentially leading to legal penalties and loss of trust.

Mitigation Strategies

Immediately update CordysCRM to version 1.9.2 or later. Apply the patch from the official repository which adds @CsPermission annotations to the sortModule methods in ContractController.java, OpportunityController.java, and OrderController.java to enforce update permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108701. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart