ZeroHour

CVE-2026-90934

moderate

Field-Level Security Bypass Exposes Attendee Emails in EspoCRM

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

EspoCRM before version 10.0.4 contains an authorization flaw (CWE-863) in the meeting and call attendees endpoints, where ACL scope validation incorrectly checks permissions on the parent event rather than on the attendee entity itself. An authenticated user with access to a meeting or call can query attendee data through these endpoints and read email addresses that field-level security rules are supposed to hide. The attacker gains disclosure of restricted contact information (attendee email addresses) for other users and records they would not otherwise be permitted to view, giving it a CVSS 4.0 base score of 8.7 (high). Any self-hosted or cloud EspoCRM deployment running a version earlier than 10.0.4 is affected, particularly those relying on field-level email restrictions. No public proof-of-concept is known and the vulnerability is not listed in the CISA KEV catalog, so exploitation in the wild is not currently evidenced.

What to do: Upgrade EspoCRM to version 10.0.4 or later, where the attendee entity ACL validation is corrected. Review server and application logs for authenticated accounts that queried meeting or call attendee endpoints to recover hidden email addresses, and rotate or re-restrict contact data if leakage is confirmed. As a defense-in-depth measure, verify that field-level security on email fields is enforced for all user roles and limit unnecessary access to the attendees endpoints.

Affected
EspoCRMbefore 10.0.4
Estimated exposure
moderate≈ a few thousand internet-exposed EspoCRM instances, plus additional internal deployments — EspoCRM is a self-hosted open-source CRM with no public active-install telemetry; public internet scans typically show low-thousands of exposed EspoCRM dashboards, with more running on intranets, so this is an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions.

Weakness
CWE-863
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.