Twenty CRM vulnerability exposed plaintext mailbox passwords to workspace members
A security flaw in Twenty CRM, designated CVE-2026-105763, exposed mailbox passwords in cleartext to any workspace member. The vulnerability affects versions 1.20.10 up to, but not including, 2.7.0. Remediation requires upgrading to version 2.7.0 or later, which encrypts credentials and restricts access. Administrators must also rotate all exposed mailbox passwords externally due to the prior plaintext exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in