SB2026092240 - Authorization bypass through user-controlled key in EspoCRM
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose another user's stored IMAP password.
The vulnerability exists due to an insecure direct object reference in PersonalAccountService when accessing an Email Account record using a known record ID. A remote user can access another user's Email Account record to disclose another user's stored IMAP password.
Exploitation requires access to the Email Account scope, and obtaining the victim record ID is usually not trivial.
Remediation
Install update from vendor's website.