logo

Warning: High authentication vulnerability in EspoCRM, Patch Immediately!

ID: 442eaf68-01f3-5bb0-87fb-6df59582a958

STIX ID: report--442eaf68-01f3-5bb0-87fb-6df59582a958

Feed Name: CCB Advisories Feed

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-07-24

...
...

EspoCRM CVE-2020-37094 (CWE-639) affects EspoCRM versions <= 5.8.5 and permits attackers to bypass authorization by manipulating/decoding authorization tokens to access other user accounts and administrative data (CVSS 8.7). The Centre for Cybersecurity Belgium recommends prompt patching and increased monitoring/detection to mitigate impact and identify intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.