EspoCRM <= 9.3.3 contains an authenticated server-side request forgery caused by improper internal-host validation using alternative IPv4 formats in HostCheck::isNotInternalHost(), letting authenticated users access internal resources via /api/v1/Attachment/fromImageUrl endpoint.
id: CVE-2026-33534
info:
name: EspoCRM <= 9.3.3 - Server-Side Request Forgery
author: EntroVyx
...