Unauthorized Access to Plaintext Credentials in Twenty CRM Platform
CVE-2026-105763

9.6CRITICAL

Key Information:

Vendor

Twentyhq

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105763?

Twenty, an open-source CRM platform, has a vulnerability that allows unauthorized workspace members to access sensitive connection parameters, including plaintext IMAP, SMTP, and CalDAV passwords, associated with other users' connected accounts. This issue arises from a lack of proper authentication and authorization checks for the /metadata GraphQL connectedAccounts query. Users could exploit this flaw to gain control over third-party services, leading to potential breaches of confidentiality and privacy. The vulnerability is addressed in version 2.7.0, emphasizing the importance of keeping software updated to protect sensitive information.

Affected Version(s)

twenty >= 1.20.10, < 2.7.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.