These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-105832 debrief: EspoCRM before 10.0.6 contains an authentication bypass vulnerability on unauthenticated routes, allowing attackers to bypass two-factor authentication. Defenders should assess exposure and prioritize verification and remediation. The vulnerability has a medium severity and affects EspoCRM deployments. Verify authentication configurations and two-factor authentication settings to [truncated]
CVE-2026-105831 debrief: EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form. The vulnerability allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data, which is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record. Defenders should assess exposure and potential impact, particularly thos [truncated]
CVE-2026-92298 is a vulnerability in EspoCRM versions up to 10.0.8, where the application uses PHP's rand() function to generate tokens, which can be guessed by remote unauthenticated attackers. This allows them to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details. The vulnerability has a medium severity and defenders should assess exposure and veri [truncated]
CVE-2026-90934 is a field-level security bypass vulnerability in EspoCRM before 10.0.4, allowing authenticated users to read restricted email addresses of meeting and call attendees. The vulnerability is caused by incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions. This issue may lead to unintended data exposure in sensitive deployments. Defenders sh [truncated]
CVE-2026-88896 is a server-side request forgery vulnerability in EspoCRM before version 10.0.4. The vulnerability allows an attacker to bypass internal-host validation and CURLOPT_RESOLVE IP-pinning checks by using IPv6 transition addresses, causing EspoCRM to issue outbound requests to internal network services. This could lead to unauthorized access to internal network services, potentially resulting in [truncated]
A broken access control vulnerability in EspoCRM 9.3.3 allows low-privileged users to persistently modify note pinning status without proper authorization. The flaw exists in the POST /api/v1/Note/{id}/pin endpoint where the server processes the write operation before validating permissions, resulting in a 'write first, authorize later' execution pattern. While the API returns a 403 Forbidden response, th [truncated]
EspoCRM versions prior to 9.3.5 contain an authorization bypass vulnerability in the email template preparation endpoint. The POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter to resolve the owning entity (Contact, Lead, Account, or User) without performing an access control list (ACL) check. An authenticated attacker with EmailTemplate read permission can extract all field [truncated]
CVE-2026-33741 affects EspoCRM versions 9.3.3 and below. The issue stems from SVG attachments being uploadable through normal attachment-capable fields and then rendered as top-level inline content through attachment and image entry points. That creates a stored cross-user XSS condition reachable through an ordinary workflow. The response CSP blocks inline SVG script, but the same-origin external script a [truncated]
CVE-2020-37094 details an authentication token reuse vulnerability in EspoCRM 5.7.0 prior to 5.9.0. This vulnerability allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, bypassing the victim's 2FA protections [truncated]