Description
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication bypass via incomplete two‑factor process
Action: Patch promptly
AI Analysis

Impact

EspoCRM versions prior to 10.0.6 allow an attacker to skip the second factor of two‑factor authentication when accessing specific routes that do not require authentication. By knowing a 2FA‑enabled user’s username and password, an attacker can complete the login only to the point of the first factor and then read configuration parameters that are not normally exposed. The primary impact is unauthorized disclosure of sensitive configuration data, potentially aiding further attacks.

Affected Systems

The vulnerability affects EspoCRM as distributed by the EspoCRM project. All installations running a version older than 10.0.6 are impacted; newer releases are not susceptible.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Based on the description, the attacker must have valid user credentials and can exploit the flaw via unauthenticated routes that bypass the second authentication factor. The risk is therefore limited to confidentiality compromise of configuration settings rather than full system compromise.

Generated by OpenCVE AI on October 8, 2026 at 15:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest EspoCRM release (10.0.6 or newer) to fix the 2FA bypass
  • If updating immediately is not possible, remove or protect the unauthenticated routes that allow the bypass until a patch can be applied
  • Configure the system to enforce two‑factor authentication on all entry points and restrict access to sensitive configuration data to authenticated users only

Generated by OpenCVE AI on October 8, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.
Title EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes
First Time appeared Espocrm
Espocrm espocrm
Weaknesses CWE-287
CPEs cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
Vendors & Products Espocrm
Espocrm espocrm
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:48:33.906Z

Reserved: 2026-10-05T21:59:09.591Z

Link: CVE-2026-105832

cve-icon Vulnrichment

Updated: 2026-10-08T14:48:28.540Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:35.697

Modified: 2026-10-08T15:17:35.840

Link: CVE-2026-105832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:00:06Z

Weaknesses