TL;DR
A Twenty CRM vulnerability, CVE-2026-105763, let any workspace member read other members’ IMAP, SMTP and CalDAV passwords in plaintext. The flaw scores 9.6 on CVSS and needs only the default Member role. Twenty fixed it in version 2.7.0.
- CVE: CVE-2026-105763
- CVSS: 9.6 (Critical · CVSSv3)
- Product: twentyhq twenty
- Affected: >= 1.20.10, < 2.7.0
- Impact: Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
Twenty is an open-source CRM that many teams self-host as a Salesforce alternative. Leaked mail credentials reach far beyond the CRM. According to the advisory, an attacker could “read, send and delete their mail, and to pivot via password reset to any third-party account reachable from that mailbox.”
So far, no exploitation in the wild or public proof-of-concept has been confirmed.
How the Attack Works
The bug is a plaintext password disclosure in the GraphQL API. The /metadata query connectedAccounts returned connection details for every account in a workspace. For IMAP, SMTP and CalDAV accounts, those details included the password, stored in plaintext.
Twenty hid other secrets, such as access and refresh tokens. However, the connectionParameters field was left exposed. The lookup also ignored who was asking. As a result, “any workspace member could read the cleartext IMAP/SMTP/CalDAV password, host, port and username of every other member.” Workspaces using only Google or Microsoft OAuth were not affected.
Affected Versions
- Twenty 1.20.10 up to, but not including, 2.7.0
- All 2.6.x releases (no 2.6 patch contains the fix)
Versions 1.20.9 and earlier are safe. The field stayed hidden until a later refactor re-exposed it.
Patch and Mitigation Steps
Upgrade to Twenty 2.7.0 or later. The fix hides the field, scopes lookups to the caller and encrypts credentials at rest. Note that the upgrade is a breaking change for connected account storage, so read the release notes first.
Above all, treat every IMAP, SMTP or CalDAV password entered into an affected workspace as compromised. Rotate those passwords at the mail provider, as the Twenty CRM GitHub security advisory recommends. This step matters most where this Twenty CRM vulnerability met untrusted workspace members.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!