PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108705 1Panel-dev CVE debrief

CVE-2026-108705 is a missing authorization vulnerability in CordysCRM through version 1.9.3, specifically in the POST /custom-form/data/import endpoint. This allows authenticated users to import data into any custom form by customFormId. Low-privileged attackers can upload Excel files with importType ADD or UPDATE to create records in, or overwrite existing records of, custom forms they cannot manage.

Vendor
1Panel-dev
Product
CordysCRM
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders and administrators of CordysCRM systems should assess exposure, especially in environments where low-privileged users have access to the affected endpoint. They should verify if their systems are using vulnerable versions and implement necessary mitigations.

Why it matters

CVE-2026-108705 is a missing authorization vulnerability in CordysCRM that allows low-privileged users to import data into custom forms they cannot manage, potentially leading to unauthorized data imports and overwrites. Defenders should prioritize verifying exposure, restricting access to the affected endpoint, and monitoring for suspicious data imports.

  • Potential unauthorized data imports by low-privileged users
  • Risk of data overwrite or creation in custom forms without proper authorization
  • Need for verification of CordysCRM version and custom form configurations
  • Potential impact on data integrity and system security

Technical summary

The vulnerability exists in the POST /custom-form/data/import endpoint of CordysCRM through version 1.9.3. It allows authenticated users to import data into any custom form by customFormId, enabling low-privileged attackers to upload Excel files with importType ADD or UPDATE to create or overwrite records in custom forms they cannot manage. This could lead to unauthorized data imports and overwrites, potentially impacting data integrity and system security. Defenders should prioritize verifying exposure of CordysCRM custom forms to unauthorized data imports, especially in systems where low-privileged users have access to the POST /custom-form/data/import endpoint.

Defensive priority

Defenders should prioritize verifying exposure of CordysCRM custom forms to unauthorized data imports, especially in systems where low-privileged users have access to the POST /custom-form/data/import endpoint.

Recommended defensive actions

  • Verify CordysCRM version and custom form configurations
  • Restrict access to the POST /custom-form/data/import endpoint
  • Monitor for suspicious data imports
  • Implement additional authorization checks for custom form data imports
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the corpus does not establish versions beyond 1.9.3, exploitation, impact, or remediation, which require verification from the supplied official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108705 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108705

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108705 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108705

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/form/controller/CustomFormDataController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/form/service/CustomFormDataService.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/CordysCRM/poc_custom_form_data_import.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/cordyscrm-through-1.9.3-missing-authorization-via-custom-form-data-import

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.