CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-306",
"CWE-639"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63647.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63647.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "162092298023779250647569139820112961626",
"length": 1468
},
"id": "CVE-2026-63647-18ab98b7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
"function": "translateConditionValue"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "2169227249485403836733026536955779330",
"length": 774
},
"id": "CVE-2026-63647-42c635ef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseService.java",
"function": "addClient"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"13647614030539891900209547784948376122",
"177302053198085789546864309713875756748",
"266894628680622095877158504816806573176",
"232440938878962504416225006544188930118",
"178703801923108454215267151507721668507",
"192191908576210986075135055054423048148",
"36104370984581612745691606069775050486",
"226463385340970811546259663739999254662",
"66629506080729363135913074973083795406"
],
"threshold": 0.9
},
"id": "CVE-2026-63647-4ea6879e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseController.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"69284159231027381988068726735708236427",
"153326549275395043884608174236663226870",
"5675912135259305242487244083456446787",
"56719794282321096053600032141952913913"
],
"threshold": 0.9
},
"id": "CVE-2026-63647-87c055f9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseService.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"217812939056286841266395275268640102149",
"112649252043734703874402543615723832883",
"9542532045047258073951761393684157135",
"28296968785308045174767419136619848648",
"228433550119071121396002305461679498584",
"35146771633655077929448576682560713025",
"319280518914851753663922389570993635345",
"271364206980095722046413727674352920001",
"339560178953728291259690786389009651538",
"300900461281234157190806591390512445806",
"103703906955608730734220357469991331918",
"19547618076417822620797207647310498111",
"63343417572325930389556308272247458458",
"245965094932134568814809606081854351698",
"277687008640471514107504531046236159549",
"62947647734143272223532411887300930590",
"112719122728509182566157424399589548650",
"178214851372768858833257926120475849828",
"30317570930917599866909196851440052374",
"128353985762766684865884753961420633346",
"164797241620460892049041186176867166239",
"16734381131808925585213888148389091397",
"30889538224285882168071080513375358594",
"119755695838275159855151270148254098589",
"937805274976244451436987247581916516",
"81290013791334087637306511718992775616"
],
"threshold": 0.9
},
"id": "CVE-2026-63647-8af001bd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "215529080361755172337497536441095427735",
"length": 456
},
"id": "CVE-2026-63647-da0a2627",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
"function": "translateConditionFieldName"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "84143096089906834140995583650045534772",
"length": 211
},
"id": "CVE-2026-63647-e375c81f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseController.java",
"function": "broadcast"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "95042265967127000982874536480550717966",
"length": 875
},
"id": "CVE-2026-63647-ec7e36ed",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
"function": "translateStageValue"
}
}
]
"2026-09-20T14:13:50Z"