PatchSiren cyber security CVE debrief
CVE-2026-92402 ChangeWeDer CVE debrief
A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The manipulation results in missing authorization. The attack can be launched remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
- Vendor
- ChangeWeDer
- Product
- crm
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for ChangeWeDer crm deployments should assess exposure and prioritize verification of the vulnerable component. They should also review system configurations and access controls to mitigate potential risks. Additionally, defenders should monitor for potential exploitation attempts and implement compensating controls if necessary.
Why it matters
Defenders should prioritize verifying the presence of the vulnerable component and assessing exposure, as the product does not use versioning and no official remediation is available.
- Verify exposure by reviewing system configurations and access controls.
- Implement compensating controls to mitigate potential risks.
- Monitor for potential exploitation attempts.
Technical summary
The vulnerability affects the function index of the file UserController.java in the component top.upstudy.crm.controller.UserController, allowing remote attackers to exploit missing authorization. This issue affects the product ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. The product does not use versioning, making it difficult to determine affected and unaffected releases. Defenders should prioritize verifying the presence of the vulnerable component and assessing exposure, as no official remediation is available.
Defensive priority
Defenders should prioritize verifying the presence of the vulnerable component and assessing exposure, as the product does not use versioning and no official remediation is available.
Recommended defensive actions
- Verify the presence of the vulnerable component in your environment.
- Assess exposure by reviewing system configurations and access controls.
- Implement compensating controls to mitigate potential risks.
- Monitor for potential exploitation attempts.
- Review system configurations for potential vulnerabilities.
- Track exceptions and retest remediated assets.
- Implement additional security measures to prevent exploitation.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but information about affected and unaffected releases is unavailable due to the product not using versioning. Defenders should verify the presence of the vulnerable component and assess exposure. The vulnerability affects the function index of the file UserController.java in the component top.upstudy.crm.controller.UserController, allowing remote attackers to exploit missing authorization.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92402 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92402
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92402 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92402
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ChangeWeDer/crm/
-
Source reference
Unverified legacy reference
URL: https://github.com/ChangeWeDer/crm/issues/3
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-92402
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/940349
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/405553
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/405553/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.