Authorization bypass through user-controlled key in EspoCRM - #VU152743
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose contents of another user's attachment.
The vulnerability exists due to authorization bypass through a user-controlled key in EspoCRM's import workflow when processing an Import request with an attacker-controlled attachment ID. A remote user can create an Import record using another user's known attachment ID and export its errors to disclose contents of another user's attachment.
Exploitation requires access to the Import scope and knowledge of the target attachment ID.