PatchSiren cyber security CVE debrief
CVE-2026-108705 1Panel-dev CVE debrief
CVE-2026-108705 is a missing authorization vulnerability in CordysCRM through version 1.9.3, specifically in the POST /custom-form/data/import endpoint. This allows authenticated users to import data into any custom form by customFormId. Low-privileged attackers can upload Excel files with importType ADD or UPDATE to create records in, or overwrite existing records of, custom forms they cannot manage.
- Vendor
- 1Panel-dev
- Product
- CordysCRM
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders and administrators of CordysCRM systems should assess exposure, especially in environments where low-privileged users have access to the affected endpoint. They should verify if their systems are using vulnerable versions and implement necessary mitigations.
Why it matters
CVE-2026-108705 is a missing authorization vulnerability in CordysCRM that allows low-privileged users to import data into custom forms they cannot manage, potentially leading to unauthorized data imports and overwrites. Defenders should prioritize verifying exposure, restricting access to the affected endpoint, and monitoring for suspicious data imports.
- Potential unauthorized data imports by low-privileged users
- Risk of data overwrite or creation in custom forms without proper authorization
- Need for verification of CordysCRM version and custom form configurations
- Potential impact on data integrity and system security
Technical summary
The vulnerability exists in the POST /custom-form/data/import endpoint of CordysCRM through version 1.9.3. It allows authenticated users to import data into any custom form by customFormId, enabling low-privileged attackers to upload Excel files with importType ADD or UPDATE to create or overwrite records in custom forms they cannot manage. This could lead to unauthorized data imports and overwrites, potentially impacting data integrity and system security. Defenders should prioritize verifying exposure of CordysCRM custom forms to unauthorized data imports, especially in systems where low-privileged users have access to the POST /custom-form/data/import endpoint.
Defensive priority
Defenders should prioritize verifying exposure of CordysCRM custom forms to unauthorized data imports, especially in systems where low-privileged users have access to the POST /custom-form/data/import endpoint.
Recommended defensive actions
- Verify CordysCRM version and custom form configurations
- Restrict access to the POST /custom-form/data/import endpoint
- Monitor for suspicious data imports
- Implement additional authorization checks for custom form data imports
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the corpus does not establish versions beyond 1.9.3, exploitation, impact, or remediation, which require verification from the supplied official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108705 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108705
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108705 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108705
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/form/controller/CustomFormDataController.java
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/CordysCRM/blob/0d7ae06fe94f4ce33ec7f65b9d82a07ae05c2d94/backend/crm/src/main/java/cn/cordys/crm/form/service/CustomFormDataService.java
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/CordysCRM/poc_custom_form_data_import.py
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/cordyscrm-through-1.9.3-missing-authorization-via-custom-form-data-import
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.