Espocrm · Espocrm · CVE-2026-92298
**Name of the Vulnerable Software and Affected Versions**
EspoCRM versions prior to 10.0.9
**Description**
The software uses the PHP `rand()` function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs. Because `rand()` is not a cryptographically secure generator, remote unauthenticated attackers can guess these approximately 31-bit tokens. This allows attackers to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details.
**Recommendations**
Update EspoCRM to version 10.0.9 or later.