PatchSiren cyber security CVE debrief
CVE-2026-108704 1Panel-dev CVE debrief
CVE-2026-108704 is an authorization bypass vulnerability in CordysCRM through version 1.9.3. Low-privileged authenticated users can bypass permission checks by manipulating the owner field in requests to the follow/record/add endpoints, allowing them to add follow-up records and overwrite follow_time and follower on any known customer, clue, or opportunity.
- Vendor
- 1Panel-dev
- Product
- CordysCRM
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for CordysCRM systems, particularly those with low-privileged user accounts, should assess exposure and implement compensating controls. They should also prioritize verifying exposure, implementing compensating controls, and monitoring for suspicious activity on customer, clue, and opportunity records. Additionally, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor
Why it matters
CVE-2026-108704 is a medium-severity authorization bypass vulnerability in CordysCRM that allows low-privileged authenticated users to manipulate records. Defenders should prioritize verifying exposure, implementing compensating controls, and monitoring for suspicious activity.
- Verification of exposure and potential impact on customer, clue, and opportunity records is required.
- Defenders must implement compensating controls to restrict access to follow/record/add endpoints.
- Monitoring for suspicious activity on customer, clue, and opportunity records is necessary.
Technical summary
The vulnerability allows low-privileged authenticated users to bypass permission checks by setting the owner field to their own user id in requests to the follow/record/add endpoints, enabling them to add follow-up records and overwrite follow_time and follower on any known customer, clue, or opportunity. This is an authorization bypass vulnerability in CordysCRM through version 1.9.3, which can be exploited by low-privileged users to manipulate records. The vulnerability has a medium severity and requires defenders to prioritize verifying exposure and implementing compensating controls.
Defensive priority
Defenders should prioritize verifying exposure and implementing compensating controls, as the vulnerability allows low-privileged users to manipulate records.
Recommended defensive actions
- Verify exposure by checking system versions and user privileges
- Implement compensating controls to restrict access to follow/record/add endpoints
- Monitor for suspicious activity on customer, clue, and opportunity records
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification. The vulnerability affects CordysCRM through version 1.9.3, and low-privileged authenticated users can bypass permission checks by manipulating the owner field in requests to the follow/record/add endpoints. Defenders should verify exposure, implement compensating controls, and monitor for suspicious activity on customer, clue, and opportunity records. Evidence from the CVE Program and
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108704 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108704
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108704 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108704
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/clue/controller/ClueFollowRecordController.java
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/customer/controller/CustomerFollowRecordController.java
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/follow/controller/FollowUpRecordController.java
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/follow/service/BaseFollowUpService.java
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/CordysCRM/poc_follow_record_add.py
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/cordyscrm-through-1.9.3-authorization-bypass-via-follow-up-record-add-endpoints
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.