Authorization bypass through user-controlled key in EspoCRM - #VU152743

 

Authorization bypass through user-controlled key in EspoCRM - #VU152743

Published: September 29, 2026


Vulnerability identifier: #VU152743
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose contents of another user's attachment.

The vulnerability exists due to authorization bypass through a user-controlled key in EspoCRM's import workflow when processing an Import request with an attacker-controlled attachment ID. A remote user can create an Import record using another user's known attachment ID and export its errors to disclose contents of another user's attachment.

Exploitation requires access to the Import scope and knowledge of the target attachment ID.


Affected software

EspoCRM

Remediation

Install security update from vendor's website.

EspoCRM - update to 10.0.7

External References

Related Security Bulletins