PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90934 espocrm CVE debrief

CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. The vulnerability is caused by incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions. This issue may lead to unintended data exposure in sensitive deployments. Defenders should verify and remediate this vulnerability, especially in environments with sensitive email address data. The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected deployments is limited.

Vendor
espocrm
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-23
Advisory published
2026-09-14
Advisory updated
2026-09-23

Who should care

Defenders and administrators of EspoCRM instances should assess exposure and prioritize remediation, especially those with sensitive email address data. This vulnerability may lead to unintended data exposure, and defenders should verify and remediate it to prevent potential security breaches. Those responsible for EspoCRM deployments should review and update ACL configurations, monitor for suspicious activity, and consider compensating controls for at.

Why it matters

CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. Defenders should prioritize verifying and remediating this vulnerability, especially in sensitive deployments.

  • Authenticated users may access restricted email addresses
  • Potential data exposure for sensitive deployments
  • Verification of ACL configurations is necessary
  • Remediation requires updating to EspoCRM 10.0.4 or later

Technical summary

The vulnerability is caused by incorrect ACL scope validation in EspoCRM versions before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. This issue arises from the incorrect validation of parent event permissions instead of attendee entity permissions, potentially leading to data exposure. The vulnerability affects EspoCRM instances, particularly those with sensitive email address data. Defenders should prioritize verifying and remediating this vulnerability in EspoCRM instances.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in EspoCRM instances, especially those with sensitive email address data.

Recommended defensive actions

  • Verify EspoCRM version and apply patch 10.0.4 or later
  • Review and update ACL configurations for meeting and call attendees
  • Monitor for suspicious activity related to email address access
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is confirmed in EspoCRM versions before 10.0.4. The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected deployments is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90934 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90934

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90934 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90934

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.