Medium severity4.3NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-105832
CVE-2026-105832
Description
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.