CVE-2026-108703
Deferred Deferred - Pending Action

Missing Authorization in CordysCRM Allows Approval Status Manipulation

Vulnerability report for CVE-2026-108703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

CordysCRM through 1.9.3 contains a missing authorization vulnerability in POST /approval-resource/push that allows authenticated users to submit any resource for approval without ownership checks. Low-privileged attackers can supply arbitrary resourceId values for contracts, invoices, quotations or orders to alter their approval status and read approval details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
1Panel-dev CordysCRM 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CordysCRM through version 1.9.3 has a missing authorization vulnerability in the POST /approval-resource/push endpoint. This flaw allows authenticated users to submit any resource for approval without verifying ownership. Attackers with low privileges can manipulate the approval status of contracts, invoices, quotations, or orders by providing arbitrary resourceId values, potentially altering their approval state and accessing approval details.

Detection Guidance

To detect this vulnerability, monitor POST requests to /approval-resource/push endpoint for unusual activity. Check for requests with arbitrary resourceId values from low-privileged users. Review logs for approval status changes without proper authorization. Use the provided PoC script to test if the endpoint lacks permission checks.

Impact Analysis

Low-privileged attackers could alter approval statuses of business resources like contracts or invoices without authorization. This may lead to unauthorized approvals, data integrity issues, or exposure of sensitive approval details. The vulnerability enables attackers to push approvals for any resource by specifying a target resource ID.

Compliance Impact

This vulnerability could lead to unauthorized changes in approval statuses, potentially violating data integrity and access control requirements under GDPR and HIPAA. Unauthorized approvals may result in non-compliance with audit trails and record-keeping obligations.

Mitigation Strategies

Immediately update CordysCRM to a patched version beyond 1.9.3. Implement strict input validation for resourceId in the /approval-resource/push endpoint. Add ownership verification checks before processing approval requests. Restrict access to the approval-resource endpoints to authorized users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart