CVE-2026-108703: CordysCRM through 1.9.3 Missing Authorization via /approval-resource/push
CordysCRM through 1.9.3 contains a missing authorization vulnerability in POST /approval-resource/push that allows authenticated users to submit any resource for approval without ownership checks. Low-privileged attackers can supply arbitrary resourceId values for contracts, invoices, quotations or orders to alter their approval status and read approval details.
Affected Software
Event History
Frequently Asked Questions
Which deployments are known to be affected?
CordysCRM versions through 1.9.3 are identified as affected. The provided information does not identify a fixed version.
Does exploitation require prior access?
Yes. An attacker must be authenticated, but only low-privileged user access is required.
What business records could be exposed or manipulated?
An attacker can supply arbitrary resourceId values for contracts, invoices, quotations, or orders. This can alter approval status and disclose approval details for those resources.