SB2026092240 - Authorization bypass through user-controlled key in EspoCRM



SB2026092240 - Authorization bypass through user-controlled key in EspoCRM

Published: September 22, 2026

Security Bulletin ID SB2026092240
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose another user's stored IMAP password.

The vulnerability exists due to an insecure direct object reference in PersonalAccountService when accessing an Email Account record using a known record ID. A remote user can access another user's Email Account record to disclose another user's stored IMAP password.

Exploitation requires access to the Email Account scope, and obtaining the victim record ID is usually not trivial.


Remediation

Install update from vendor's website.