CVE-2026-108702
Deferred Deferred - Pending Action

Authentication Bypass in 1Panel-dev CordysCRM

Vulnerability report for CVE-2026-108702, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

1Panel-dev CordysCRM through 1.9.3 lacks a PROCESS_SETTING permission check on POST /approval-flow/webhook/test, allowing any authenticated user to trigger server-side requests to attacker-supplied URLs. Attackers can redirect GET requests from a controlled host to bypass SSRFValidator and probe internal addresses through success or failure results.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
1Panel-dev CordysCRM 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108702 is a Server-Side Request Forgery (SSRF) vulnerability in CordysCRM through version 1.9.3. It exists in the POST /approval-flow/webhook/test endpoint where authenticated users can trigger server-side requests to arbitrary URLs without proper permission checks. Attackers can bypass SSRFValidator protections and probe internal network addresses by observing success or failure responses.

Detection Guidance

To detect this vulnerability, monitor network traffic for unexpected outbound requests from the CordysCRM server, particularly to internal or restricted addresses. Check logs for POST requests to /approval-flow/webhook/test from non-admin users. Use tools like curl to test the endpoint manually: curl -X POST http://<target>/approval-flow/webhook/test -H 'Content-Type: application/json' -d '{"url":"http://attacker-controlled-server"}' and observe if the server makes a request to the specified URL.

Impact Analysis

This vulnerability allows attackers to make the server issue outbound HTTP requests to internal or restricted systems. They can probe internal network addresses, potentially accessing sensitive internal services or data. The impact includes unauthorized network reconnaissance and potential data exfiltration through crafted requests.

Compliance Impact

This vulnerability allows unauthorized server-side requests to internal or external systems, which could lead to data exfiltration or unauthorized access. For GDPR, this may violate principles of data protection and security (Article 32). For HIPAA, it could compromise protected health information by enabling unauthorized network probing or data access.

Mitigation Strategies

Immediately update CordysCRM to a version beyond 1.9.3 where the missing authorization check is fixed. If an update is not available, restrict access to the /approval-flow/webhook/test endpoint by implementing proper permission checks, such as adding @RequiresPermissions('PROCESS_SETTING_*') annotations. Temporarily disable the webhook test functionality if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108702. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart