PT-2026-95659 · Cordyscrm · Cordyscrm

CVE-2026-63646

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CordysCRM versions prior to 1.7.2
Description An authentication bypass exists in the getMcpField() function of the McpController because the ShiroFilter.addPublicPathFilters method marks the /mcp/** path as anonymous and the controller lacks a permission annotation. An unauthenticated user can access the 'GET /mcp/form/config/{formKey}' endpoint to retrieve sensitive information about CRM modules, including field names, types, required flags, default values, options, validation rules, and binding sources. This exposure allows an attacker to reconstruct the application data model to facilitate more targeted attacks against other inputs.
Recommendations Update to version 1.7.2.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63646
GHSA-46P5-M7PQ-82HM

Affected Products

Cordyscrm