Critical severity9.8NVD Advisory· Published Mar 2, 2026· Updated Jun 17, 2026
CVE-2026-26720
CVE-2026-26720
Description
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Twenty/CRMdescription
- Range: <=1.15.0
Patches
Vulnerability mechanics
References
2- dillonkirsch.com/post/locally_hosted_twenty_rce_cve_2026_26720/nvdExploitThird Party Advisory
- twenty.comnvdProduct
News mentions
0No linked articles in our index yet.