CVE-2026-76902 | 1Panel-dev CordysCRM up to 1.7.3 AttachmentService AttachmentService.getResource ID improper authorization
A vulnerability labeled as problematic has been found in 1Panel-dev CordysCRM up to 1.7.3. Affected is the function AttachmentService.getResource of the component AttachmentService. The manipulation of the argument ID results in improper authorization.
This vulnerability is reported as CVE-2026-76902. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More