CRITICAL
9.6 CVE-2026-105763 Published 6 Oct 2026
Twenty CRM GraphQL API Exposes Plaintext Email Passwords
Worried this affects your website?
Twenty, an open-source CRM platform, has fixed a GraphQL API vulnerability that exposed connected account credentials.
From version 1.20.10 through 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords. The field was not hidden, and the lookup did not enforce the calling user's identity or account visibility.
- Affected versions: 1.20.10 to 2.7.0
- Impact: A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts.
- Not affected: Google and Microsoft OAuth-only workspaces
- Fixed in: 2.7.0
Reference: CVE-2026-105763 on NVD
← Back to Security News