Authenticated service probing via unvalidated appSecret URL
Published Jul 19, 2026 · Updated Jul 19, 2026
SSRF in 1Panel-dev Cordys CRM 1.4.0 and 1.4.1 allows remote authenticated users to probe server-reachable services via appSecret. getSqlBotSrc extracts a src URL and opens a HEAD connection without validating the destination or blocking internal addresses. SYSTEM_SETTING_READ permission on the third-party test endpoint is sufficient; callbacks reveal service reachability without returning response bodies.
Summary
What happened
SSRF in 1Panel-dev Cordys CRM 1.4.0 and 1.4.1 allows remote authenticated users to probe server-reachable services via appSecret. getSqlBotSrc extracts a src URL and opens a HEAD connection without validating the destination or blocking internal addresses. SYSTEM_SETTING_READ permission on the third-party test endpoint is sufficient; callbacks reveal service reachability without returning response bodies.
The record
- CVE
- CVE-2026-16223
- Published
- Jul 19, 2026
- Updated
- Jul 19, 2026
- Vendor
- KubeOperator
- Product
- Cordys CRM
- Classifications
- CWE-918, T1190
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Jul 19, 2026CVE publishedPublication date reported by the CVE source.
- Jul 19, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1.4.0
- Affected versionversion=1.4.1
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Third-party edit endpoint appSecret callback proof of conceptproof of concept · demonstrated
- Third-party test endpoint appSecret callback proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo