CVE-2026-90934
moderateField-Level Security Bypass Exposes Attendee Emails in EspoCRM
EspoCRM before version 10.0.4 contains an authorization flaw (CWE-863) in the meeting and call attendees endpoints, where ACL scope validation incorrectly checks permissions on the parent event rather than on the attendee entity itself. An authenticated user with access to a meeting or call can query attendee data through these endpoints and read email addresses that field-level security rules are supposed to hide. The attacker gains disclosure of restricted contact information (attendee email addresses) for other users and records they would not otherwise be permitted to view, giving it a CVSS 4.0 base score of 8.7 (high). Any self-hosted or cloud EspoCRM deployment running a version earlier than 10.0.4 is affected, particularly those relying on field-level email restrictions. No public proof-of-concept is known and the vulnerability is not listed in the CISA KEV catalog, so exploitation in the wild is not currently evidenced.
What to do: Upgrade EspoCRM to version 10.0.4 or later, where the attendee entity ACL validation is corrected. Review server and application logs for authenticated accounts that queried meeting or call attendee endpoints to recover hidden email addresses, and rotate or re-restrict contact data if leakage is confirmed. As a defense-in-depth measure, verify that field-level security on email fields is enforced for all user roles and limit unnecessary access to the attendees endpoints.
| EspoCRM | before 10.0.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.