{"id":"CVE-2026-105763","summary":"Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL","details":"Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user's identity or account visibility. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. Google and Microsoft OAuth-only workspaces were not affected. This issue is fixed in version 2.7.0.","aliases":["GHSA-mq5c-qp77-2cv3"],"modified":"2026-10-06T10:48:11.173633469Z","published":"2026-10-05T23:05:56.160Z","database_specific":{"cwe_ids":["CWE-522"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105763.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105763.json"},{"type":"FIX","url":"https://github.com/twentyhq/twenty/commit/57f13c9b9230f3c4c293ea6f3d8901990e6902c4"},{"type":"FIX","url":"https://github.com/twentyhq/twenty/pull/20673"},{"type":"ADVISORY","url":"https://github.com/twentyhq/twenty/security/advisories/GHSA-mq5c-qp77-2cv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105763"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/twentyhq/twenty","events":[{"introduced":"20adb869171efe5982a7ae7c7950cd8ce97d45e1"},{"fixed":"570c57563a077a826f5c769ff91f68c2c73e3789"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.20.10"},{"fixed":"2.7.0"}]}}],"versions":["v2.6.1","v2.6.0","v2.5.2","v2.5.1","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.2","v2.0.1","v2.0.0","v1.23.9","v1.23.8","v1.23.7","v1.23.6","v1.23.5","v1.23.4","v1.23.3","v1.23.1","v1.23.0","v1.22.0","v1.21.0","v1.20.11","v1.20.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105763.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}