PatchSiren cyber security CVE debrief
CVE-2026-92298 EspoCRM CVE debrief
CVE-2026-92298 is a vulnerability in EspoCRM versions up to 10.0.8, where the application uses PHP's rand() function to generate tokens, which can be guessed by remote unauthenticated attackers. This allows them to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details. The vulnerability has a medium severity and defenders should assess exposure and verify patch application to prevent potential token guessing and unauthorized access. The CVE record and source item provide details on the vulnerability, including the use of PHP's rand() function for token generation and the potential impacts.
- Vendor
- EspoCRM
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for EspoCRM instances, particularly those using version 10.0.8 or earlier, should assess exposure and verify patch application to prevent potential token guessing and unauthorized access.
Why it matters
CVE-2026-92298 is a medium-severity vulnerability in EspoCRM that allows remote unauthenticated attackers to guess tokens generated using PHP's rand() function, potentially leading to unauthorized access or confirmation of opt-ins. Defenders should assess exposure, verify patch application, and consider additional security measures.
- Remote unauthenticated attackers can guess tokens to confirm opt-ins or access event details
- Potential for unauthorized access to event details or confirmation of opt-ins on behalf of other contacts
- Need for defenders to verify patch application and assess exposure
- Possible impact on event management and lead capture functionality
Technical summary
The EspoCRM application uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs. This can be exploited by remote unauthenticated attackers to guess the roughly 31-bit tokens and gain unauthorized access to event details or confirm opt-ins on behalf of other contacts. The vulnerability has a medium severity and defenders should assess exposure and verify patch application to prevent potential token guessing and unauthorized access. The use of PHP's rand() function for token generation is a security concern as it is not cryptographically secure.
Defensive priority
Medium priority for defenders to assess exposure and verify patch application, given the potential for token guessing and unauthorized access.
Recommended defensive actions
- Assess exposure by verifying if the EspoCRM instance is running version 10.0.8 or earlier
- Review and apply the patch commit provided by the vendor, if available
- Monitor for suspicious activity related to token guessing or unauthorized access
- Consider implementing additional security measures, such as token validation or rate limiting
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including the use of PHP's rand() function for token generation and the potential impacts. However, the corpus does not provide explicit information on exploitation or victim data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92298 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92298
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92298 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92298
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
EspoCRM through 10.0.8 Weak Token Generation via rand()
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92298.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/kazisabu/9e3109aab24245fde19b88f53f965e93
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/espocrm/espocrm/commit/8e5555c1ee0ed1e92a9ad54e62f735ac2c4051a1
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/espocrm/espocrm/blob/10.0.8/application/Espo/Core/Utils/Util.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/espocrm/espocrm/blob/10.0.8/application/Espo/Repositories/UniqueId.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/espocrm/espocrm
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/espocrm-through-10.0.8-weak-token-generation-via-rand
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.