Back to database
Act now83High8.3VulnerabilityCVE-2026-105833No patch link observed

CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account sc…

Published Oct 8, 2026, 03:17 PM UTCIngested 8h agoSource NVD(cve-db)CVE-2026-105833

Description

EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.3

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

Low

Privileges Required

UI

None

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

High

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)