Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92459— yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint

Quick assessment

Affected
guchengwuyue yshop-crm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim end

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92459

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
guchengwuyue yshop-crm 0 ~ 2.1.3 -

II. Public POCs for CVE-2026-92459

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92459

登录查看更多情报信息。

Other References for CVE-2026-92459 (6)

Same Patch Batch · guchengwuyue · 2026-09-16 · 9 CVEs total

CVE-2026-92456 7.1 HIGH yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoint
CVE-2026-92460 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing
CVE-2026-92462 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep
CVE-2026-92463 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listi
CVE-2026-92457 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice
CVE-2026-92461 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
CVE-2026-92455 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints
CVE-2026-92458 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale

IV. Related Vulnerabilities

V. Comments for CVE-2026-92459

No comments yet


Leave a comment