Missing Authorization in EspoCRM - CVE-2026-46691
Published: June 18, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Import exportErrors endpoint when handling requests for import records by ID. A remote user can send a crafted request with an arbitrary import ID to disclose sensitive information.
Exploitation requires knowledge of a valid import record ID.