Critical severity9.6NVD Advisory· Published Oct 6, 2026· Updated Oct 6, 2026
CVE-2026-105763
CVE-2026-105763
Description
Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user's identity or account visibility. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. Google and Microsoft OAuth-only workspaces were not affected. This issue is fixed in version 2.7.0.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.