CVE-2026-92298
Deferred Deferred - Pending Action

EspoCRM Token Prediction Vulnerability via rand()

Vulnerability report for CVE-2026-92298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-23

Assigner: VulnCheck

Description

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 31-bit tokens to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-23
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
espocrm espocrm to 10.0.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

EspoCRM versions prior to 10.0.8 use PHP's rand() function to generate security tokens for lead-capture opt-in, event invitations, and campaign URLs. These tokens are not cryptographically secure, allowing attackers to guess them due to low entropy. This can lead to unauthorized actions like confirming opt-ins, accepting or declining event invitations on behalf of others, and accessing event details without authentication.

Detection Guidance

Check EspoCRM version with: grep -r "version" /path/to/espocrm/application/Espo/Resources/i18n/en_US/Global.json. If version is <=10.0.8, the system is vulnerable. Inspect UniqueId.php for rand() usage in token generation.

Impact Analysis

If you use EspoCRM versions before 10.0.8, attackers could exploit this to manipulate opt-in confirmations, alter event attendance, or view sensitive event information. This could lead to misinformation, unauthorized access to data, or reputational damage for your organization. The impact depends on how the system is configured and used.

Compliance Impact

This vulnerability could violate GDPR's requirement for secure data processing and HIPAA's safeguards for protected health information by allowing unauthorized access to sensitive data. Organizations using affected versions may face compliance violations, legal penalties, or loss of trust due to insufficient security measures for token generation.

Mitigation Strategies

Upgrade to a patched version if available. Monitor for suspicious activity in lead-capture, event invitations, and campaign URLs. Restrict access to sensitive endpoints until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart