Authentication Bypass by Primary Weakness in EspoCRM - #VU151609
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose certain configuration parameters.
The vulnerability exists due to improper authentication in routes that do not require authentication when processing a login stopped at the second factor. A remote user can use a login that has not completed two-factor authentication to disclose certain configuration parameters.
Exploitation requires knowledge of the username and password of a user with two-factor authentication enabled.