Vulnerability
Published 2026-10-05
Verified 2026-10-06

Twenty CRM CVE-2026-105763 (CVSS 9.6): any workspace member could read other members' plaintext IMAP, SMTP and CalDAV passwords through the /metadata GraphQL API — fixed in 2.7.0

Twenty, the open-source CRM, published GitHub advisory GHSA-mq5c-qp77-2cv3 (CVE-2026-105763, CVSS 3.1 9.6; CVE record published 5 October 2026). From 1.20.10 until 2.7.0, the connectedAccounts query on the /metadata GraphQL endpoint returned the connection parameters of every connected account in a workspace, including plaintext IMAP, SMTP and CalDAV passwords, because the field was not hidden and the lookup did not check the caller's identity or account visibility. An ordinary workspace member could take other members' mail and calendar credentials, read their mail or calendars, and potentially use them to reset third-party accounts. Workspaces that connect only Google or Microsoft accounts through OAuth were not affected. The advisory does not report exploitation. Primary: Twenty GitHub security advisory.

Product
Twenty open-source CRM (self-hosted and cloud) — connected email and calendar accounts
Versions
Affected: 1.20.10 to before 2.7.0. Fixed: 2.7.0 or later.
CVSS
(CVSS 3.1)
Exploited in Australia?
unknown
Patch to
Upgrade self-hosted Twenty to 2.7.0 or later. If any workspace connected mailboxes or calendars with an IMAP, SMTP or CalDAV password on an affected version, assume those passwords were readable by every member: rotate them, prefer app-specific passwords or OAuth, and check the mail providers' sign-in logs.

Primary: Twenty GHSA-mq5c-qp77-2cv3 — plaintext IMAP/SMTP/CalDAV password disclosure via /metadata GraphQL (CVE-2026-105763) · Vendor: Twenty — Release v2.7.0 · CVE: CVE-2026-105763 · CVE-2026-105763 record (published 5 Oct 2026)

vulnerabilities identity cloud