CVE-2026-88896 | EspoCRM up to 10.0.3 Host Validation /Attachment/fromImageUrl ipAddressIsNotInternal server-side request forgery

SecurityVulns

A vulnerability labeled as critical has been found in EspoCRM up to 10.0.3. This issue affects the function HostCheck::ipAddressIsNotInternal of the file /Attachment/fromImageUrl of the component Host Validation. Executing a manipulation can lead to server-side request forgery.

This vulnerability is handled as CVE-2026-88896. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More