Improper access control in EspoCRM - CVE-2026-46694
Published: June 18, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the portal Note API endpoint when fetching a single note directly. A remote user can request a note with a known ID to disclose sensitive information.
Exploitation requires knowledge of the note ID and stream access to the parent record.