CVE-2026-105832: Espocrm
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.
Affected products
- Espocrm Espocrm: before 10.0.6 (fixed in 10.0.6)
Published 2026-10-08. Last modified 2026-10-08.