SB2026092927 - Multiple vulnerabilities in EspoCRM
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose contents of another user's attachment.
The vulnerability exists due to authorization bypass through a user-controlled key in EspoCRM's import workflow when processing an Import request with an attacker-controlled attachment ID. A remote user can create an Import record using another user's known attachment ID and export its errors to disclose contents of another user's attachment.
Exploitation requires access to the Import scope and knowledge of the target attachment ID.
2) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose restricted email address values.
The vulnerability exists due to incorrect authorization in the address-book search API when processing address-book search requests. A remote user can search accessible records to disclose restricted email address values.
Access to the relevant record is required.
3) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose values of restricted audited fields.
The vulnerability exists due to improper access control in the Note read endpoint when retrieving a note associated with a parent record. A remote user can request a note identifier displayed in the stream to disclose values of restricted audited fields.
The user must be allowed to access the parent record's stream while being forbidden from reading the audited field.
Remediation
Install update from vendor's website.