Weak Token Generation in EspoCRM Affects Multiple Features
CVE-2026-92298
6.3MEDIUM
What is CVE-2026-92298?
EspoCRM versions up to 10.0.8 utilize PHP's rand() function for generating tokens involved in crucial features such as lead-capture opt-in, event invitations, and campaign URLs. This approach fails to provide a secure entropy source, allowing remote unauthenticated attackers to exploit the weakness by guessing the approximately 31-bit tokens. Such exploitation enables attackers to confirm opt-ins, manage event invitations fraudulently, and potentially access sensitive event details improperly.
Affected Version(s)
EspoCRM 0 <= 10.0.8
