Input Validation Flaw in Twenty CRM Allows Arbitrary SQL Execution
CVE-2026-73069
9.1CRITICAL
What is CVE-2026-73069?
The vulnerability in the Twenty CRM platform allows users with DATA_MODEL permission to manipulate the system's TS_VECTOR searchVector, potentially executing arbitrary SQL commands in the application database. This occurs through insecure handling of input during PATCH requests and GraphQL mutations, endangering the integrity and security of user data. The issue has been addressed in version 2.15.0, emphasizing the need for timely updates to safeguard against such risks.
Affected Version(s)
twenty < 2.15.0
