External risk intelligence

CordysCRM Unauthenticated Access to User Data and Channel Control.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-63647

CordysCRM is a customer relationship management system, a type of software commonly deployed as an internet-facing web application for organizational use. The vulnerability exists in SSE endpoints that are reachable over the network, and CRM platforms are typically designed to be accessible to users in various locations, making them a common target for external network reachability.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects CordysCRM, an open-source customer relationship management system. It allows unauthenticated access to sensitive user information and the ability to inject or terminate user data streams. The main concern is confirming relevance and exposure.

  • Access to user data without login.
  • Sensitive workflow and alert information exposed.
  • Confirm if CordysCRM is used.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can interact with CordysCRM's Server-Sent Events (SSE) endpoints. By sending requests to `/sse/subscribe`, `/sse/broadcast`, or `/sse/close`, an attacker can potentially view other users' sensitive workflow data, inject messages into their streams, or terminate their connections. This is possible because the system trusts user-provided identifiers instead of verifying authenticated user sessions.

  • Accessible over the network without authentication.
  • Triggered by sending requests to SSE endpoints.
  • Allows unauthorized access to user data.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated user to access another user's workflow events, approval requests, mentions, and alerts within the CordysCRM system. It also enables the injection of system messages into another user's data stream and the termination of their communication channel.

  • User-specific sensitive information.
  • Unauthenticated access to user data.
  • Unauthorized access and disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in CordysCRM impacts organizations using private deployments of the system. The platform team or the application owners are likely responsible for addressing this issue, as it affects the core functionality of the CRM. The first practical step is to identify all instances of CordysCRM, confirm their reachability and business criticality, and then coordinate remediation efforts.

  • Identify affected deployments and owners.
  • Verify external reachability and impact.
  • Plan and execute updates or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is CordysCRM and how is it used?

CordysCRM is an open-source, AI-driven customer relationship management platform. Organizations deploy it privately to track client interactions, manage workflows, and handle internal business communications. Because it is designed to centralize sensitive data, it serves as a critical repository for business processes, approval requests, and team alerts that rely on secure, authenticated connections to function correctly.

What is the vulnerability in CVE-2026-63647?

This CVE involves a failure in access control, categorized as missing authentication (CWE-306) and an authorization bypass (CWE-639). The system fails to verify if a user is truly who they claim to be when interacting with specific Server-Sent Events (SSE) endpoints. Instead of using a secure, verified session, the software trusts a user ID provided directly in the request, allowing unauthorized individuals to impersonate or access data streams belonging to others.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specifically crafted network requests to the unauthenticated SSE endpoints—specifically subscribe, broadcast, or close. These actions do not require any valid login credentials to succeed. It is important to note that simply visiting the platform's main page is not the cause; the vulnerability specifically exists in these backend messaging channels which incorrectly bypass standard security filters.

Is my instance of CordysCRM relevant to this threat?

If you host CordysCRM, your instance is likely relevant. According to Halo Surface Signal, this software is typically deployed as an internet-facing web application, increasing the risk of network-based exploitation. While internal deployments face fewer risks from the open internet, the vulnerability allows anyone with network reachability to the SSE endpoints to view or disrupt active user sessions, making it a priority for all administrators.

What should I do first to address CVE-2026-63647?

The most effective first step is to upgrade your CordysCRM installation to version 1.7.2 or later, which contains the official fix. Before applying updates, create an inventory of all your CordysCRM deployments to ensure no legacy or test environments are overlooked. Once updated, confirm the fix by verifying that the SSE endpoints no longer accept anonymous requests and now properly enforce authenticated user sessions.

References