CVE-2026-63647Critical· 9.3▾ AbyssalPoC availableCordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 51.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63646Medium· 6.9CordysCRM is an open source AI-powered customer relationship management system that supports private deployment
CVE-2026-76902Medium· 5.0CordysCRM is an open source AI-powered customer relationship management system that supports private deployment
CVE-2026-76901Medium· 5.8CordysCRM is an open source AI-powered customer relationship management system that supports private deployment
CVE-2026-76899Medium· 5.7CordysCRM is an open source AI-powered customer relationship management system that supports private deployment
CVE-2026-76900Medium· 6.8CordysCRM is an open source AI-powered customer relationship management system that supports private deployment
CVE-2026-52745Medium· 5.3CordysCRM is an open source AI-powered customer relationship management system that supports private deployment