Description
EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions.
Published: 2026-09-14
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Attendee Email Addresses
Action: Immediate Patch
AI Analysis

Impact

EspoCRM before version 10.0.4 contains a field‑level security bypass in the meeting and call attendees endpoints that allows an authenticated user to read email addresses that should be hidden. By sending a request to the attendees endpoint, an attacker can bypass the intended field‑level protection because the system checks the permissions on the parent event instead of on each attendee record. This results in unauthorized disclosure of private attendee contact information.

Affected Systems

EspoCRM systems running any release prior to 10.0.4 are impacted. The affected product is espocrm:espocrm and the issue is present in all versions below 10.0.4.

Risk and Exploitability

Based on the description, it is inferred that the vulnerability requires an authenticated session to access the affected endpoints. The CVSS score of 8.7 indicates a high severity impact. The absence of an EPSS score and the fact that the flaw is not listed in the CISA KEV catalog suggest that widespread exploitation is unlikely as of the current data. Nevertheless, because the attack path uses legitimate API calls, an attacker with legitimate user credentials can retrieve the hidden emails without triggering obvious alarms, making the risk noteworthy for environments where attendee email privacy is a regulatory or business requirement.

Generated by OpenCVE AI on September 14, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade EspoCRM to version 10.0.4 or later, which incorporates the ACL fix.
  • After upgrading, review and enforce attendee access‑control settings to restrict email visibility to authorized roles only.
  • Monitor user activity logs for suspicious retrieval of attendee data and audit ACL configurations regularly.

Generated by OpenCVE AI on September 14, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions.
Title EspoCRM before 10.0.4 Field-level Security Bypass via Attendees
First Time appeared Espocrm
Espocrm espocrm
Weaknesses CWE-863
CPEs cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
Vendors & Products Espocrm
Espocrm espocrm
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:12:16.603Z

Reserved: 2026-09-14T11:33:51.886Z

Link: CVE-2026-90934

cve-icon Vulnrichment

Updated: 2026-09-14T17:32:42.622Z

cve-icon NVD

Status : Received

Published: 2026-09-14T13:19:31.830

Modified: 2026-09-14T19:18:12.967

Link: CVE-2026-90934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:00:09Z

Weaknesses