Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63647— CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`

Quick assessment

Affected
1Panel-dev CordysCRM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CordysCRM 是一个支持私有化部署的开源 AI 驱动的客户关系管理系统。在 1.7.2 版本之前, 中的 、 和 端点对匿名访问开放。这是因为 方法将 SSE 路径配置为公共路径,允许未经身份验证的请求访问;同时,这些端点信任调用者传入的 参数,而非从已认证的用户身份(principal)中推导用户标识。 由于缺乏基于会话的身份验证机制,未认证的调用者可以: 通过 读取其他用户的工作流事件、审批请求、提及消息和警报; 通过 向其他用户的流中注入 消息; 通过 终止其他用户的 SSE 连接。 该漏洞已在 1.7

CVSS 9.3 · Critical

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63647

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
Source: CVE Program / CVE List V5
Vulnerability Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Panel-dev CordysCRM < 1.7.2 -

II. Public POCs for CVE-2026-63647

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63647

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63647 (2)

Vendor Advisories for CVE-2026-63647 (1)

Other References for CVE-2026-63647 (1)

Same Patch Batch · 1Panel-dev · 2026-09-18 · 7 CVEs total

CVE-2026-63646 6.9 MEDIUM CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users
CVE-2026-76900 6.8 MEDIUM CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runt
CVE-2026-76901 5.8 MEDIUM CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoint
CVE-2026-76899 5.7 MEDIUM CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`
CVE-2026-52745 5.3 MEDIUM CordysCRM: Customer Public Pool Sorting Field SQL Injection
CVE-2026-76902 5.0 MEDIUM CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/

IV. Related Vulnerabilities

V. Comments for CVE-2026-63647

No comments yet


Leave a comment