CVE-2020-37094
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
03/02/2026
Last modified:
03/03/2026
Description
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* | 5.8.5 (including) |
To consult the complete list of CPE names with products and versions, see this page



