Junglewise Threat Intelligence

CVE-2026-88896: EspoCRM server-side request forgery via IPv6 transition address bypass

CVE-2026-88896 · Severity: medium · CVSS 5.3 · Published 2026-09-10

Technologies: Espocrm. Vendors: Espocrm.

Executive brief

EspoCRM is a customer relationship management system used to manage business interactions and data. The application contains a flaw in its outbound URL validation that allows attackers to bypass internal-network protections by using IPv6 transition addresses. An authenticated attacker can exploit this through image attachment uploads or webhook delivery to cause the server to make requests to internal services, potentially exposing sensitive data or causing operational disruption.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw in the HostCheck::ipAddressIsNotInternal() validation function. The function strips IPv4-mapped IPv6 prefixes (::ffff:) but fails to recognize IPv6 transition addresses (NAT64, 6to4, Teredo) that embed private IPv4 addresses. An attacker controlling a domain with AAAA DNS records pointing to these transition addresses can bypass both the internal-host validation and CURLOPT_RESOLVE IP-pinning checks. This allows EspoCRM to issue outbound requests to internal network services. Exploitation requires authentication with attachment access for POST /Attachment/fromImageUrl, or admin/API credentials for webhook delivery. The issue is patched in EspoCRM 10.0.4.

Affected products

  • EspoCRM EspoCRM before 10.0.4

Timeline

  • 2026-08-13: disclosed: GitHub Security Advisory published
  • 2026-09-10: advisory: CVE-2026-88896 published
  • 2026-08-13: patched: Fix available in version 10.0.4

References

Related threats