securityonline.info 6 Oct 2026, 01:56 UTC

Twenty CRM flaw exposed users’ email passwords to all workspace members

Twenty CRM flaw exposed users’ email passwords to all workspace members
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

TWENTY CRM has fixed a critical flaw, CVE-2026-105763, that allowed any workspace member to read other users’ plaintext IMAP, SMTP and CalDAV passwords via the GraphQL /metadata connectedAccounts query. The exposure includes host, port, username and the passwords themselves, while access and refresh tokens were kept hidden. The vulnerability stems from a field that was unintentionally accessible to all members regardless of the caller, and the issue did not affect workspaces using only Google or Microsoft OAuth.

Affected versions run from Twenty 1.20.10 up to but not including 2.7.0, with all 2.6.x releases impacted. Version 1.20.9 and earlier are safe. Twenty CRM’s advisory states the fix in Twenty 2.7.0 hides the sensitive field, scopes lookups to the caller, and encrypts credentials at rest. Organisations should treat all IMAP, SMTP or CalDAV passwords in affected workspaces as compromised and rotate them with their mail providers.

The upgrade to 2.7.0 is breaking for connected account storage, so owners should consult the release notes before upgrading. At present there is no confirmed exploitation in the wild.

View full article

Article by CyberSIXT