CVE-2026-105763
Deferred Deferred - Pending Action

Twenty CRM Plaintext Credential Exposure via Metadata GraphQL Query

Vulnerability report for CVE-2026-105763, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user's identity or account visibility. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. Google and Microsoft OAuth-only workspaces were not affected. This issue is fixed in version 2.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
twentyhq twenty >= 1.20.10, < 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105763 is a critical vulnerability in the Twenty CRM platform where plaintext IMAP, SMTP, and CalDAV passwords were exposed to any workspace member via a GraphQL query. The /metadata endpoint returned connectionParameters containing unencrypted credentials, allowing unauthorized access to email and calendar data.

Detection Guidance

To detect this vulnerability, check if your Twenty CRM instance is running a vulnerable version (1.20.10 to 2.6.x). Use the GraphQL query /metadata to see if connectionParameters returns plaintext passwords. Commands include: curl -X POST -H 'Content-Type: application/json' -d '{"query":"{connectedAccounts {connectionParameters}}"}' http://your-server/graphql.

Verify database encryption status for connectionParameters. Check logs for unauthorized GraphQL queries to /metadata. Ensure no legacy schemas or DTOs expose passwords.

Impact Analysis

An attacker with workspace member access could retrieve other users' external service credentials and potentially reset third-party accounts. This could lead to unauthorized access to emails, calendars, and sensitive data, posing a high risk of data breaches and account takeovers.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal and sensitive data. It could result in non-compliance penalties, reputational damage, and legal consequences for organizations handling protected information.

Mitigation Strategies

Upgrade to Twenty CRM version 2.7.0 or later immediately. Rotate all exposed IMAP, SMTP, and CalDAV passwords if upgrading is not possible. Restrict GraphQL /metadata query access.

Revoke and reissue OAuth tokens for affected accounts. Audit user roles to ensure only necessary members have access. Monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105763. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart