CRITICAL 9.6 CVE-2026-105763 Published 6 Oct 2026

Twenty CRM GraphQL API Exposes Plaintext Email Passwords

Worried this affects your website?

Twenty, an open-source CRM platform, has fixed a GraphQL API vulnerability that exposed connected account credentials.

From version 1.20.10 through 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords. The field was not hidden, and the lookup did not enforce the calling user's identity or account visibility.

  • Affected versions: 1.20.10 to 2.7.0
  • Impact: A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts.
  • Not affected: Google and Microsoft OAuth-only workspaces
  • Fixed in: 2.7.0

Reference: CVE-2026-105763 on NVD

← Back to Security News