CVE-2026-105833

high

Description

EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.

References

https://www.vulncheck.com/advisories/espocrm-before-10.0.5-idor-via-personalaccount-service-exposes-imap-passwords

https://github.com/espocrm/espocrm/security/advisories/GHSA-pj52-qx2q-4qfp

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95020

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 8.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.0022