CVE-2026-105832
EUVD-2026-9501908.10.2026, 15:17
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| espocrm | espocrm | 𝑥 < 10.0.6 | CNA |
Common Weakness Enumeration