Incorrect authorization in EspoCRM - #VU152745

 

Incorrect authorization in EspoCRM - #VU152745

Published: September 29, 2026


Vulnerability identifier: #VU152745
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose values of restricted audited fields.

The vulnerability exists due to improper access control in the Note read endpoint when retrieving a note associated with a parent record. A remote user can request a note identifier displayed in the stream to disclose values of restricted audited fields.

The user must be allowed to access the parent record's stream while being forbidden from reading the audited field.


Affected software

EspoCRM

Remediation

Install security update from vendor's website.

EspoCRM - update to 10.0.7

External References

Related Security Bulletins