PT-2026-93700 · Yshop-Crm · Yshop-Crm

·

CVE-2026-92456

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions yshop-crm versions prior to 2.1.4
Description Insufficient authorization enforcement on the 'saveRedisSet' and 'getRedisSet' endpoints within the CrmCustomerController allows authenticated back-office users to read and modify installation-wide lead-allocation and customer auto-recycling policies. By manipulating shared Redis keys that control customer auto-recycling behavior, an attacker can cause mass customer data deletion, disable lead recycling, or block the creation of new customers across the entire deployment.
Recommendations Update yshop-crm to version 2.1.4 or later. As a temporary mitigation, restrict access to the 'saveRedisSet' and 'getRedisSet' endpoints in the CrmCustomerController.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92456

Affected Products

Yshop-Crm