CVE-2026-105832
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's username and password can skip the second factor to read config parameters not exposed publicly.