Critical SSRF Vulnerability in CordysCRM Exposed
Article Content
- •CVE-2026-76900 affects CordysCRM v1.7.3, allowing SSRF attacks.
- •Authenticated users can exploit the flaw to access internal URLs.
- •The vulnerability is fixed in version 1.7.4, released after September 25, 2026.
CordysCRM version 1.7.3 has a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-76900. This flaw allows authenticated users to manipulate webhook URLs, potentially targeting internal resources and cloud metadata services. The vulnerability arises from a lack of SSRF validation in the approval workflow's webhook execution path, which can lead to unauthorized internal network reconnaissance and service interactions. The issue affects any deployment of CordysCRM that grants the PROCESS_SETTING_ADD permission to users. The vulnerability was published on September 18, 2026, and is fixed in version 1.7.4. Security professionals are urged to update to the latest version to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-76900 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents Plugin4Shell is a critical zero-click remote code execution vulnerability affecting four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. Discovered by AIR Security, this flaw allows attackers to exploit trusted plugin marketplaces by swapping legitimate plugins with malicious ones, gaining…
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability allows attackers to force Axios to call arbitrary endpoints, with a public exploit already available. As…