CVE-2026-105832: Espocrm

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.

Affected products

  • Espocrm Espocrm: before 10.0.6 (fixed in 10.0.6)

Published 2026-10-08. Last modified 2026-10-08.