CVE-2026-105833
Deferred Deferred - Pending Action

Insecure Direct Object Reference in EspoCRM Exposes IMAP Credentials

Vulnerability report for CVE-2026-105833, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
espocrm espocrm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in EspoCRM versions before 10.0.5. It allows users with Email Account scope access to retrieve other users' stored IMAP passwords by exploiting a known Email Account record ID. Attackers can then access the victim's mailbox using the stolen credentials.

Detection Guidance

To detect this vulnerability, check EspoCRM versions before 10.0.5. Inspect network logs for unauthorized requests to PersonalAccount\Service endpoints targeting Email Account records. Look for unusual IMAP password retrieval attempts or access to known record IDs.

Impact Analysis

If you are an EspoCRM user with Email Account scope access, an attacker could steal your IMAP password and gain unauthorized access to your email mailbox. This could lead to exposure of sensitive communications, personal data, or other confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using vulnerable versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Immediately upgrade EspoCRM to version 10.0.5 or later. Review and restrict access to the Email Account scope for users. Audit existing Email Account records for unauthorized access or password exposure. Rotate any exposed IMAP passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105833. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart