Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel-dev
1panel-dev cordyscrm |
|
| Vendors & Products |
1panel-dev
1panel-dev cordyscrm |
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CordysCRM through 1.9.3 contains a missing authorization vulnerability in POST /approval-resource/push that allows authenticated users to submit any resource for approval without ownership checks. Low-privileged attackers can supply arbitrary resourceId values for contracts, invoices, quotations or orders to alter their approval status and read approval details. | |
| Title | CordysCRM through 1.9.3 Missing Authorization via /approval-resource/push | |
| First Time appeared |
Fit2cloud
Fit2cloud cordys Crm |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:fit2cloud:cordys_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fit2cloud
Fit2cloud cordys Crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:12:29.098Z
Reserved: 2026-10-10T23:08:48.070Z
Link: CVE-2026-108703
No data.
Status : Deferred
Published: 2026-10-11T02:16:38.803
Modified: 2026-10-11T02:16:38.937
Link: CVE-2026-108703
No data.
OpenCVE Enrichment
Updated: 2026-10-11T03:30:13Z
