Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-63647: CordysCRM allows unauthorized SSE stream access
CVE-2026-63647 · published 10 days ago
Summary
In versions before 1.7.2, CordysCRM exposed public endpoints that let anyone listen to or interfere with another user's real‑time notifications. An unauthenticated person could view workflow events, approvals, mentions, or even stop a user's notification channel. Upgrade to version 1.7.2 or later to close these public endpoints.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| 1panel-dev | cordyscrm | < 1.7.2 |
Original advisory text
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
References
- https://github.com/1Panel-dev/CordysCRM/pull/2719 Patch
- https://github.com/1Panel-dev/CordysCRM/commit/6cb81deb53434ae7792673c50312ff916... Patch
- https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.2 URL
- https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-9qg8-cm35-xqp4 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63647... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-63647 Vendor Advisory
Severity
9.4
Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta