CVE-2026-16222
Last modified
CVE-2026-16222 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of the argument mkAddress results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 1Panel-dev | CordysCRM | 1.4.0; 1.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-16222?
How severe is CVE-2026-16222?
How do I fix CVE-2026-16222?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16217A security vulnerability has been detected in guohongze admi…6.3
- CVE-2026-16218A vulnerability was detected in hunvreus devpush up to 0.4.6…2.6
- CVE-2026-16219A flaw has been found in Croogo CMS up to 4.0.7. This affect…6.3
- CVE-2026-1622Neo4j Enterprise and Community editions versions prior to 20…4.8
- CVE-2026-16220A vulnerability has been found in code-projects Online Exami…4.3
- CVE-2026-16221Impact: fast-uri versions from 2.3.1 through 4.1.0 (includin…7.5
- CVE-2026-16223A vulnerability was determined in 1Panel-dev CordysCRM up to…6.3
- CVE-2026-16224A vulnerability was identified in jxxghp MoviePilot up to 2.…5.3
- CVE-2026-16225A security flaw has been discovered in davenardella snap7 up…6.3
- CVE-2026-16226A weakness has been identified in SourceCodester Pizzafy Eco…5.1
- CVE-2026-16227A security vulnerability has been detected in SourceCodester…7.3
- CVE-2026-16228A vulnerability was detected in SourceCodester Class and Exa…7.3
Are you affected by CVE-2026-16222?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
