Skip to content
Critical SSRF Vulnerability in CordysCRM Exposed

Critical SSRF Vulnerability in CordysCRM Exposed

First seen 25 Sep 2026, 15:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 17:52 UTC
  • •CVE-2026-76900 affects CordysCRM v1.7.3, allowing SSRF attacks.
  • •Authenticated users can exploit the flaw to access internal URLs.
  • •The vulnerability is fixed in version 1.7.4, released after September 25, 2026.

CordysCRM version 1.7.3 has a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-76900. This flaw allows authenticated users to manipulate webhook URLs, potentially targeting internal resources and cloud metadata services. The vulnerability arises from a lack of SSRF validation in the approval workflow's webhook execution path, which can lead to unauthorized internal network reconnaissance and service interactions. The issue affects any deployment of CordysCRM that grants the PROCESS_SETTING_ADD permission to users. The vulnerability was published on September 18, 2026, and is fixed in version 1.7.4. Security professionals are urged to update to the latest version to mitigate risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
CVE-2026-76900 published
The SSRF vulnerability in CordysCRM was disclosed to the National Vulnerability Database.
Sentinelone
2026-09-24
NVD database updated
The National Vulnerability Database updated details regarding CVE-2026-76900.
Sentinelone
2026-09-25
GitHub Security Advisory released
GitHub published an advisory detailing the SSRF vulnerability in CordysCRM, emphasizing the lack of validation in webhook execution.
github.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76900 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed