PatchSiren cyber security CVE debrief
CVE-2026-90934 espocrm CVE debrief
CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. The vulnerability is caused by incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions. This issue may lead to unintended data exposure in sensitive deployments. Defenders should verify and remediate this vulnerability, especially in environments with sensitive email address data. The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected deployments is limited.
- Vendor
- espocrm
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-23
Who should care
Defenders and administrators of EspoCRM instances should assess exposure and prioritize remediation, especially those with sensitive email address data. This vulnerability may lead to unintended data exposure, and defenders should verify and remediate it to prevent potential security breaches. Those responsible for EspoCRM deployments should review and update ACL configurations, monitor for suspicious activity, and consider compensating controls for at.
Why it matters
CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. Defenders should prioritize verifying and remediating this vulnerability, especially in sensitive deployments.
- Authenticated users may access restricted email addresses
- Potential data exposure for sensitive deployments
- Verification of ACL configurations is necessary
- Remediation requires updating to EspoCRM 10.0.4 or later
Technical summary
The vulnerability is caused by incorrect ACL scope validation in EspoCRM versions before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. This issue arises from the incorrect validation of parent event permissions instead of attendee entity permissions, potentially leading to data exposure. The vulnerability affects EspoCRM instances, particularly those with sensitive email address data. Defenders should prioritize verifying and remediating this vulnerability in EspoCRM instances.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in EspoCRM instances, especially those with sensitive email address data.
Recommended defensive actions
- Verify EspoCRM version and apply patch 10.0.4 or later
- Review and update ACL configurations for meeting and call attendees
- Monitor for suspicious activity related to email address access
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is confirmed in EspoCRM versions before 10.0.4. The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected deployments is limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90934 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90934
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90934 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90934
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/espocrm/espocrm/security/advisories/GHSA-hpgx-8qg3-5w7v
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/espocrm-before-10.0.4-field-level-security-bypass-via-attendees
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.