CVE-2026-92401: ChangeWeDer crm improper authentication
A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction, according to the supplied vector.
Which deployments should be treated as potentially affected?
ChangeWeDer crm deployments at or before commit c07bd4c97141521af6475034bc58523beed51bbd are identified as affected. Because the project uses continuous delivery with rolling releases, no affected or fixed release versions are available.
Is a fix available from the project?
The project was notified through an issue report but had not responded at the time of publication. The provided data does not identify a patched release or workaround.