CVE-2026-108692: 1Panel-dev CordysCRM 1.9.0 before 1.9.2 Missing Authorization via /field/source Endpoints
1Panel-dev CordysCRM from 1.9.0 before 1.9.2 contains a missing authorization vulnerability in eight ModuleFieldController /field/source data-source endpoints lacking permission checks. Authenticated users denied module permission can page through organization-wide leads, contacts, quotations, contracts, payment plans, payment records, orders and invoices owned by other users.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated CordysCRM user who is denied permission to a relevant module may still exploit the affected /field/source endpoints. The issue does not require user interaction and can be reached over the network.
What information could be exposed?
Affected endpoints can allow paging through organization-wide records owned by other users, including leads, contacts, quotations, contracts, payment plans, payment records, orders, and invoices. The stated impact is confidentiality only; integrity and availability impacts are not indicated.
Are default deployments affected?
The available information identifies affected versions from 1.9.0 before 1.9.2, but does not state whether the vulnerable endpoints or permissions configuration are enabled by default.
How can we determine whether we are exposed?
Check whether the deployment runs CordysCRM version 1.9.0 or a version earlier than 1.9.2. In an authorized test, use an authenticated account denied access to a module and verify whether its corresponding /field/source endpoint returns records belonging to other users.