Authentication Bypass in EspoCRM Affects User Security
CVE-2026-105832

5.3MEDIUM

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-105832?

EspoCRM versions prior to 10.0.6 contain a vulnerability that allows unauthorized access by bypassing two-factor authentication on certain routes. Attackers with knowledge of a 2FA-enabled user's valid credentials can evade the second factor requirement, granting them access to potentially sensitive configuration parameters that are otherwise shielded from public view. This flaw compromises user data security and necessitates immediate attention.

Affected Version(s)

espocrm 0 < 10.0.6

espocrm 10.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Humbertosp
.