CVE-2026-105832
Deferred Deferred - Pending Action

Authentication Bypass in EspoCRM via 2FA Skip

Vulnerability report for CVE-2026-105832, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
espocrm espocrm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

EspoCRM before version 10.0.6 has an authentication bypass flaw where a login attempt stopping at the second factor is incorrectly accepted on routes that do not require authentication. Attackers with a 2FA-enabled user's username and password can bypass the second factor to access restricted configuration parameters.

Detection Guidance

To detect this vulnerability, check if your EspoCRM instance is running a version before 10.0.6. Use commands like 'curl -s http://your-espocrm-url/ | grep "EspoCRM"' to identify the version. If the version is 10.0.5 or earlier, the system is vulnerable.

Impact Analysis

If you use EspoCRM versions 10.0.5 or earlier with 2FA enabled, an attacker could gain access to sensitive configuration data by bypassing authentication. This could lead to unauthorized changes or exposure of system settings.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing restricted configuration parameters.

Mitigation Strategies

Immediately upgrade EspoCRM to version 10.0.6 or later to patch the authentication bypass. Verify the upgrade by checking the version again using the same commands mentioned for detection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105832. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart