chiprook
← Security
SecurityOctober 9, 2026, 12:00

CVE-2026-105763 in Twenty CRM exposed mailbox passwords in cleartext

CVE-2026-105763 in Twenty CRM versions 1.20.10 through 2.7.0 exposed stored mailbox passwords in cleartext to any workspace member. The 2.7.0 release hides the field, scopes lookups to the caller and encrypts credentials, but passwords must still be rotated at the mail provider.

CVE-2026-105763 in Twenty CRM exposed mailbox passwords in cleartext
#Twenty
Read next
Security

CVE-2026-104610: 12,055 Tenda gateways exposed to the internet

Security

Check Point VPN CVE-2026-85102: R81.20–R82.10 affected, 1,852 exposed instances

Security

CVE-2026-87799 in LXD: rsync and btrfs receive exposed, optimized ZFS not affected

Security

ZoomEye: 6,050 VeloCloud Orchestrator systems exposed online amid CVE-2026-93952