CVE-2026-7782: CodeCanyon Perfex CRM Tenant Clients.php project authorization
A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7782?
CVE-2026-7782 is considered critical due to the potential for unauthorized access in CodeCanyon Perfex CRM.
How can I fix CVE-2026-7782?
To fix CVE-2026-7782, update your CodeCanyon Perfex CRM installation to version 3.4.2 or later.
What component is affected by CVE-2026-7782?
CVE-2026-7782 affects the Clients::project function in the application/controllers/Clients.php file.
Who is impacted by CVE-2026-7782?
Users of CodeCanyon Perfex CRM version up to 3.4.1 are impacted by CVE-2026-7782.
What kind of vulnerability is CVE-2026-7782?
CVE-2026-7782 is an authorization vulnerability that allows for user impersonation and data access.