GHSA-9h5f-ghfx-jfjcMediumCVSS 4.3

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.

🔗 References (4)