Incorrect authorization in EspoCRM - #VU152745
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose values of restricted audited fields.
The vulnerability exists due to improper access control in the Note read endpoint when retrieving a note associated with a parent record. A remote user can request a note identifier displayed in the stream to disclose values of restricted audited fields.
The user must be allowed to access the parent record's stream while being forbidden from reading the audited field.