Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33534

35
FAUCET Score

EspoCRM versions 9.3.3 and below contain an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows attackers to bypass internal-host validation by using alternative IPv4 representations such as octal notation. The vulnerability exists in the HostCheck::isNotInternalHost() function, which fails to recognize alternative IP formats, causing validation to incorrectly treat requests to loopback addresses as safe. An authenticated user can exploit this through the /api/v1/Attachment/fromImageUrl endpoint to force the server to make requests to internal services and retrieve the responses as attachments. The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector, low complexity, and requirement for valid user authentication. The impact is limited to confidentiality disclosure, with no integrity or availability impact, as attackers can only read responses from internal resources accessible to the application. The EPSS score of 0.0003 indicates minimal real-world exploitation likelihood compared to other vulnerabilities. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and the KEV status is inactive. Community attention appears minimal based on the available data. EspoCRM released version 9.3.4 to address this issue, and organizations should prioritize patching systems running vulnerable versions, particularly in environments where users with API access may pose a risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.3.4CPE matchmatch criteria
cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.98%
Probability of exploitation in next 30 days
EPSS Percentile
78.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-33534 · May 8, 2026
ExploitDB: EDB-52583 · May 27, 2026
This CVE's current EPSS score of 0.0198 is in the 91st percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / espocrm/espocrm/releases/tag/9.3.4
Release Notes
github.com / espocrm/espocrm/security/advisories/GHSA-h7gx-8gwv-7g73
ExploitVendor Advisory