Incorrect authorization in EspoCRM - #VU152744
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose restricted email address values.
The vulnerability exists due to incorrect authorization in the address-book search API when processing address-book search requests. A remote user can search accessible records to disclose restricted email address values.
Access to the relevant record is required.