CVE-2026-41141 | EspoCRM up to 9.3.4 Management Application /api/v1/EmailTemplate/ emailAddress authorization (GHSA-vvmh-mf4h-96hw)

SecurityVulns

A vulnerability described as problematic has been identified in EspoCRM up to 9.3.4. This vulnerability affects unknown code of the file /api/v1/EmailTemplate/ of the component Management Application. The manipulation of the argument emailAddress results in authorization bypass.

This vulnerability was named CVE-2026-41141. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More