CVE-2026-92298
EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 31-bit tokens to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-338
- Published
- 2026-09-16
- Last modified
- 2026-09-17
Affected products
- EspoCRM EspoCRM
Weakness type
Related vulnerabilities
- CVE-2025-3495 — COMMGR - Insufficient Randomization Authentication Bypass
- CVE-2025-66565 — Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
- CVE-2025-54883 — Vision UI's security-kit Contains Cryptographic Weakness
- CVE-2025-66630 — Fiber insecurely fallsback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
- CVE-2025-67504 — WBCE CMS has Weak Random Number Generator in Password Generation Function
- CVE-2025-15618 — Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key
- CVE-2022-36045 — Account takeover via cryptographically weak PRNG in NodeBB Forum
- CVE-2021-43799 — RabbitMQ exposes ports with weak default secrets in Zulip Server