Unauthorized Access to Plaintext Credentials in Twenty CRM Platform
CVE-2026-105763
9.6CRITICAL
What is CVE-2026-105763?
Twenty, an open-source CRM platform, has a vulnerability that allows unauthorized workspace members to access sensitive connection parameters, including plaintext IMAP, SMTP, and CalDAV passwords, associated with other users' connected accounts. This issue arises from a lack of proper authentication and authorization checks for the /metadata GraphQL connectedAccounts query. Users could exploit this flaw to gain control over third-party services, leading to potential breaches of confidentiality and privacy. The vulnerability is addressed in version 2.7.0, emphasizing the importance of keeping software updated to protect sensitive information.
Affected Version(s)
twenty >= 1.20.10, < 2.7.0
