CVE-2026-105833 - EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords
CVE ID :CVE-2026-105833 Published : Oct. 8, 2026, 3:17 p.m. | 2 hours, 11 minutes ago Description :EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP...