CVE-2026-7782Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 105-0405-05
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-051
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7782 Authorization Bypass in CodeCanyon Perfex CRM Up to 3.4.1 Tenant Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7782

    Post summary

    The text announces CVE-2026-7782 as an authorization bypass in Perfex CRM v3.4.1- (Tenant Handler), without providing PoC, exploit details, patch information, or evidence of active exploitation.

    0000043
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7782 A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the com… https://www.cve.org/CVERecord?id=CVE-2026-7782 ----- Traducción: CVE-2026-7782 Se … http://infoflow.cloud`

    Post summary

    A new CVE-2026-7782 vulnerability was identified in CodeCanyon Perfex CRM (up to version 3.4.1), specifically affecting the Clients::project function; the post merely discloses the issue without providing a PoC, exploit, patch, or evidence of active exploitation.

    0000026
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7782 A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the com… https://www.cve.org/CVERecord?id=CVE-2026-7782

    Post summary

    The post only notes that CVE‑2026‑7782 was detected in Perfex CRM up to v3.4.1, with no further details or remedial information.

    00000163
    57.4K followersView on X

Explore more