CVE-2026-105763 in Twenty CRM exposed mailbox passwords in cleartext
CVE-2026-105763 in Twenty CRM versions 1.20.10 through 2.7.0 exposed stored mailbox passwords in cleartext to any workspace member. The 2.7.0 release hides the field, scopes lookups to the caller and encrypts credentials, but passwords must still be rotated at the mail provider.
- Twenty CRM 1.20.10 up to 2.7.0 is affected, including all 2.6.x releases
- Any Member-role user could read IMAP, SMTP and CalDAV credentials
- Version 2.7.0 encrypts credentials and scopes connected account lookups
- Rotate passwords at the mail host: patching does not undo the exposure
Read next
Security