External risk intelligence

Twenty CRM GraphQL Exposure of External Service Credentials

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-105763

Twenty is a CRM platform commonly deployed as a web-based application accessible to users via the internet. Because it functions as a centralized business service, instances are frequently exposed to network access to facilitate remote team collaboration, making the application surface and its GraphQL endpoints commonly reachable in standard deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Twenty CRM platform could expose plaintext passwords for external services, such as email and calendars. If exploited, a user with standard access could view or misuse the credentials of other users, potentially leading to unauthorized access to mail and calendar data, and even the ability to reset third-party accounts. This issue affects versions prior to 2.7.0.

  • Plaintext passwords for external services were exposed.
  • Normal users could access other users' mail and calendar data.
  • Confirm Twenty CRM relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with standard access within a workspace can potentially steal the external service credentials of other workspace members. This occurs because the platform's GraphQL endpoint for connected accounts improperly exposes sensitive information, such as IMAP, SMTP, and CalDAV passwords, without verifying the user's identity or visibility permissions. If successful, an attacker could gain unauthorized access to linked email and calendar services, and possibly take control of those third-party accounts.

  • Requires standard workspace access.
  • Triggered by querying connected account metadata.
  • Risk of credential theft and account compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a normal workspace member could access other members' external-service credentials, including plaintext IMAP, SMTP, and CalDAV passwords. This exposure could enable unauthorized access to mail or calendars and potentially lead to the resetting of third-party accounts. Google and Microsoft OAuth-only workspaces are not affected.

  • Plaintext external-service credentials.
  • Unauthorized GraphQL query execution.
  • Compromised mail and calendar access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and system owners should prioritize identifying all Twenty instances within their environment. Since this vulnerability exposes sensitive credentials through a GraphQL query accessible to any workspace member, the immediate first step is to confirm if the affected instances are externally reachable and if they host business-critical data. Once identified and validated, engage the platform or application owners to verify the scope of exposure and plan remediation, which may involve coordinating with vendors if custom integrations are in place or if direct patching is not feasible.

  • Platform or application owners must address.
  • Verify external reachability and criticality.
  • Plan targeted remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Twenty CRM?

Twenty is an open-source customer relationship management (CRM) platform designed to help teams manage their business interactions. It functions as a centralized hub where users integrate external services like email, calendars, and contacts. Because it handles these connections, the platform stores configuration data, such as authentication details for various third-party services, allowing users to coordinate their work and communication flows directly within the CRM environment.

How does CVE-2026-105763 expose credentials?

This vulnerability is classified as CWE-522, which relates to insufficiently protected credentials. In affected versions, the GraphQL API failed to properly check if a user had permission to view another member's account information. Consequently, a request to the system could return sensitive data—specifically plaintext passwords for IMAP, SMTP, or CalDAV services—belonging to other workspace users instead of restricting the data to the owner's account.

Do I need administrator access to trigger this bug?

No, administrative privileges are not required. The issue resides within the standard workspace functionality. Any authenticated workspace member, regardless of their role or permission level, can execute the specific GraphQL query to retrieve credentials belonging to other members. However, workspaces that rely exclusively on Google or Microsoft OAuth for authentication are not susceptible to this password exposure.

Why is this a concern for my organization?

This is a significant concern because Twenty is often deployed as a web-based application reachable via the internet, as noted by Halo Surface Signal. If your instance is internet-facing to support remote collaboration, an attacker with a standard user account can move beyond their own workspace permissions to steal credentials for linked mail and calendar services, potentially gaining broader unauthorized access to your team's sensitive business communications.

When should I prioritize fixing this for my Twenty installation?

You should prioritize this immediately if your instance is running a version older than 2.7.0. Your first step is to confirm your version and check if your deployment is reachable over the internet. Since this flaw allows users to access others' credentials without special permissions, work with your platform owners to update to version 2.7.0 or higher, which resolves the identity and visibility enforcement issues in the GraphQL query.

References