Input Validation Flaw in Twenty CRM Allows Arbitrary SQL Execution
CVE-2026-73069

9.1CRITICAL

Key Information:

Vendor

Twentyhq

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73069?

The vulnerability in the Twenty CRM platform allows users with DATA_MODEL permission to manipulate the system's TS_VECTOR searchVector, potentially executing arbitrary SQL commands in the application database. This occurs through insecure handling of input during PATCH requests and GraphQL mutations, endangering the integrity and security of user data. The issue has been addressed in version 2.15.0, emphasizing the need for timely updates to safeguard against such risks.

Affected Version(s)

twenty < 2.15.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.