Skip to content

Menu
  • Home
Menu

CVE-2026-105763 – Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL

Posted on October 6, 2026
CVE ID :CVE-2026-105763

Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago

Description :Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user’s identity or account visibility. A normal workspace member could obtain other members’ external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. Google and Microsoft OAuth-only workspaces were not affected. This issue is fixed in version 2.7.0.

Severity: 9.6 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-105763

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

Immediately isolate any systems running the potentially vulnerable component. This involves removing them from the network or placing them into a quarantined segment to prevent further exploitation or lateral movement.
Block all external network access to the affected systems, allowing only essential, pre-approved internal management traffic if absolutely necessary.
Review system logs, application logs, and web server access logs for any indicators of compromise (IOCs) such as unusual process execution, unexpected outbound network connections, file modifications, or suspicious HTTP requests.
Initiate forensic readiness procedures. This includes taking snapshots of virtual machine disks, collecting memory dumps, and preserving log files for detailed analysis by an incident response team.
Activate your organization's emergency change management protocol to prepare for rapid deployment of potential patches or mitigation measures.
Notify your internal incident response team and relevant stakeholders about the potential exposure.

2. PATCH AND UPDATE INFORMATION

Monitor official vendor advisories and security bulletins for the affected software component. Since this CVE is not yet indexed, the vendor is the primary source for accurate patch information.
Prepare for rapid deployment of patches once they become available. This includes having a robust patch management process, an established test environment, and a rollback plan.
Prioritize testing of any vendor-supplied patches in a non-production environment to ensure stability, compatibility, and effectiveness before deploying to production systems.
If no patch is immediately available, evaluate the feasibility of temporary workarounds:
Disable or restrict access to specific features or modules within the application that are identified

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 4

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme