Authorization bypass through user-controlled key in EspoCRM - CVE-2026-46708
Published: June 18, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to modify the opt-out state of a protected contact or lead without authorization.
The vulnerability exists due to authorization bypass through a user-controlled key in target-list opt-out actions when handling opt-out requests for contacts or leads referenced through a shared target list. A remote user can send a crafted opt-out action request to modify the opt-out state of a protected contact or lead without authorization.
The issue affects cases where the user can access a shared target list but does not have read or edit access to the target contact or lead.