Description


EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.

Related CPE's


Could not find any relations

Weaknesses



CWE-522

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

7.7 · High

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T15:17:35.913Z

17 hours ago

Last modified

2026-10-08T18:17:15.000Z

14 hours ago