Authentication Vulnerability in EspoCRM by EspoCRM
CVE-2020-37094

8.6HIGH

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
3 February 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2020-37094?

EspoCRM version 5.8.5 is susceptible to an authentication vulnerability that enables attackers to gain unauthorized access to other user accounts. By manipulating authorization headers, including Basic Authorization and Espo-Authorization tokens, an attacker can decode and alter these tokens, potentially accessing sensitive administrative user information and privileges. This vulnerability poses a significant risk, emphasizing the need for immediate attention to secure affected installations.

Affected Version(s)

EspoCRM 5.7.0 < 5.9.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Besim ALTINOK, İsmail BOZKURT
.