Authorization bypass through user-controlled key in EspoCRM - #VU151610

 

Authorization bypass through user-controlled key in EspoCRM - #VU151610

Published: September 22, 2026


Vulnerability identifier: #VU151610
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose another user's stored IMAP password.

The vulnerability exists due to an insecure direct object reference in PersonalAccountService when accessing an Email Account record using a known record ID. A remote user can access another user's Email Account record to disclose another user's stored IMAP password.

Exploitation requires access to the Email Account scope, and obtaining the victim record ID is usually not trivial.


Affected software

EspoCRM

Remediation

Install security update from vendor's website.

EspoCRM - update to 10.0.5

External References

Related Security Bulletins