Authorization bypass through user-controlled key in EspoCRM - #VU151610
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose another user's stored IMAP password.
The vulnerability exists due to an insecure direct object reference in PersonalAccountService when accessing an Email Account record using a known record ID. A remote user can access another user's Email Account record to disclose another user's stored IMAP password.
Exploitation requires access to the Email Account scope, and obtaining the victim record ID is usually not trivial.