{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/changeweder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-92401"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["crm (\u003c= c07bd4c97141521af6475034bc58523beed51bbd)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","vulnerability"],"_cs_type":"advisory","_cs_vendors":["ChangeWeDer"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-92401 exists within the ChangeWeDer crm application, specifically affecting the function \u003ccode\u003etop.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie\u003c/code\u003e. This flaw permits an unauthenticated remote attacker to manipulate session cookies to bypass authentication controls. Because the application utilizes a continuous delivery model with rolling releases, there are no specific version numbers for the affected or patched states. The vulnerability was disclosed to the developers via an issue report, but as of the publication date, no response or fix has been provided. This vulnerability presents a high risk of unauthorized access to CRM instances, as the attack can be executed remotely without prior credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to improper authentication, granting unauthorized users access to the CRM system. Depending on the privileges associated with the manipulated session, this could allow attackers to access sensitive customer data, modify CRM records, or perform administrative functions within the application, leading to significant data exposure or service disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all exposed instances of ChangeWeDer CRM within the environment to assess the current attack surface.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unusual cookie modifications or unexpected access patterns targeting the authentication flow.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to the CRM instance to trusted IP ranges until a patch is available.\u003c/li\u003e\n\u003cli\u003eMonitor the vendor's repository or release channels for updates regarding the vulnerability report and deploy patches immediately once they are issued.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T17:52:20Z","date_published":"2026-09-16T17:52:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crm-auth/","summary":"An unauthenticated remote code execution vulnerability in the LoginUserUtil.releaseUserIdFromCookie function of ChangeWeDer CRM allows attackers to bypass authentication through cookie manipulation.","title":"Improper Authentication Vulnerability in ChangeWeDer CRM","url":"https://feed.craftedsignal.io/briefs/2026-09-crm-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - ChangeWeDer","version":"https://jsonfeed.org/version/1.1"}