VYPR
Medium severity4.3NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026

CVE-2026-105832

CVE-2026-105832

Description

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.