Disclosure summary
EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 31-bit tokens to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details.
Source-reported weakness categories
CWE-338
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-92298
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- gist.github.com
- github.com
- github.com
- github.com
- github.com
- www.vulncheck.com
PUBLISHED 2026-09-15T22:17:39-04:00
MODIFIED 2026-10-08T12:18:00-04:00
INGESTED 2026-10-10T20:50:44-04:00