Description
EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.
Published: 2026-10-08
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Insecure Direct Object Reference exposing IMAP credentials
Action: Immediate Patch
AI Analysis

Impact

EspoCRM versions earlier than 10.0.5 contain an insecure direct object reference flaw in the PersonalAccount Service that permits a user with Email Account scope to request the IMAP password of any other user whose Email Account record ID is known. The vulnerability allows a malicious actor to retrieve stored IMAP credentials and consequently gain access to the victim’s mailbox, thereby violating the confidentiality of that mailbox and potentially compromising additional data visible through the email client.

Affected Systems

The affected product is EspoCRM, any deployment of versions prior to 10.0.5. The flaw is present in the PersonalAccount module of the application and is tied to the Email Account scope. Users who are granted Email Account permissions on the system are at risk when the unpatched version is in use.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires an authenticated user with Email Account scope and knowledge of the target’s Email Account record ID. Once these prerequisites are met, the attacker can directly retrieve the IMAP password without further exploitation.

Generated by OpenCVE AI on October 8, 2026 at 15:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch to upgrade EspoCRM to version 10.0.5 or later.
  • Limit the Email Account scope to only those users who require it for business purposes, and remove the scope from regular users.
  • Ensure that IMAP passwords are stored encrypted and consider rotating them after applying the patch.

Generated by OpenCVE AI on October 8, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.
Title EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords
First Time appeared Espocrm
Espocrm espocrm
Weaknesses CWE-522
CPEs cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
Vendors & Products Espocrm
Espocrm espocrm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:10:32.707Z

Reserved: 2026-10-05T22:00:10.841Z

Link: CVE-2026-105833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:35.913

Modified: 2026-10-08T15:17:36.357

Link: CVE-2026-105833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:04Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials