CVE-2020-37094
CVE-2020-37094 is a high-severity vulnerability in Espocrm with a CVSS 3.x base score of 8.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-303.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- CVSS v4: 8.6
- EPSS exploit prediction: 0% (38th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2020-31008
- Weakness: CWE-303
- Affected product: Espocrm
- Published:
- Last modified:
Description
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentication/Espo.php. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, since tokens are bound to password hashes rather than unique per-user values, bypassing the victim's 2FA protections.
Frequently asked questions
- What is CVE-2020-37094?
- EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentication/Espo.php. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, since tokens are bound to password hashes rather than unique per-user values, bypassing the victim's 2FA protections.
- How severe is CVE-2020-37094?
- CVE-2020-37094 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2020-37094 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (38th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-37094?
- CVE-2020-37094 affects Espocrm. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-37094?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2020-37094 have an EU (EUVD) identifier?
- Yes. CVE-2020-37094 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2020-31008.
- When was CVE-2020-37094 published?
- CVE-2020-37094 was published on 2026-02-03 and last updated on 2026-07-15.
References
- https://github.com/espocrm/espocrm/commit/b299220dd0c7acdaa1ed8be8ffd79c7985093c7a
- https://www.espocrm.com
- https://www.exploit-db.com/exploits/48376
- https://www.vulncheck.com/advisories/espocrm-two-factor-auth-bypass-via-auth-token-reuse-between-accounts-with-identical-passwords
EU advisories (EUVD)
Affected products (1)
- cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
More vulnerabilities in Espocrm
- CVE-2014-7985 — Critical (CVSS 10.0): Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary…
- CVE-2026-33656 — Critical (CVSS 9.1): EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in…
- CVE-2022-38843 — High (CVSS 8.8): EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any…
- CVE-2019-14351 — High (CVSS 8.8): EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a…
- CVE-2025-32390 — High (CVSS 8.5): EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in…
- CVE-2022-38844 — High (CVSS 8.0): CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating…
Other CWE-303 vulnerabilities
- CVE-2025-13390 — Critical (CVSS 10.0): The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,…
- CVE-2025-12421 — Critical (CVSS 9.9): Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that…
- CVE-2025-12419 — Critical (CVSS 9.9): Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly…
- CVE-2026-59309 — Critical (CVSS 9.8): VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with…
- CVE-2025-66489 — Critical (CVSS 9.8): Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker…
- CVE-2025-21311 — Critical (CVSS 9.8): Windows NTLM V1 Elevation of Privilege Vulnerability