Executive brief
EspoCRM is an open-source Customer Relationship Management (CRM) platform used by businesses to manage customer data and communications. A security flaw in the email import feature allows an authenticated user to access and read email attachments belonging to other users. Additionally, the exploit causes the original attachment to be deleted from the system, potentially leading to data loss and unauthorized access to sensitive business communications.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `POST /api/v1/Email/importEml` endpoint of EspoCRM. The application fails to perform adequate Access Control List (ACL) checks on the `fileId` parameter provided in the request body. While the application checks if the user has general 'Email:create' and 'Import' permissions, it does not verify if the user has authorization to access the specific attachment ID requested. An attacker can provide the ID of a `.eml` attachment belonging to another user; the system will then fetch the file, import its contents into the attacker's mailbox as a new email, and subsequently delete the original attachment record. This bypasses the standard download path which correctly enforces entity-level ACLs. The vulnerability is fixed in version 9.3.4.
Affected products
- EspoCRM EspoCRM <= 9.3.3
Timeline
- 2026-03-24: patched: Version 9.3.4 released with fix.
- 2026-04-13: advisory: GitHub Security Advisory published.
- 2026-04-13: disclosed: CVE-2026-33740 published.