CVE-2026-26720Disclosure(twenty / twenty)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch twenty twenty systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

2.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twenty

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 1 mentions (2026-03-02); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
twenty

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-15: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-04-15: 103-0203-0303-0503-0604-15
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-021
Disclosure1
2026-03-031
Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-04-151
Disclosure1
Full discourse5 posts
  • Ostorlab@OstorlabSec
    Disclosure

    We took a closer look at Twenty CRM’s serverless functions while analyzing CVE-2026-26720 and found something far more serious than expected. A “custom code” feature ends up running user-supplied TypeScript directly on the server, with no real sandbox, full environment access, and no meaningful restrictions on what can be executed. When you combine that with unauthenticated webhook triggers, it becomes possible to go from a normal workspace member to full server compromise and a persistent backdoor. This is another example of how fast “flexible” platform features turn into security boundaries when isolation is missing. Full technical breakdown in the article: https://blog.ostorlab.co/cve-2026-26720-twenty-crm-serverless-rce.html

    Post summary

    The post announces CVE-2026-26720, revealing that Twenty CRM’s serverless feature executes unsandboxed user‑supplied TypeScript and can be triggered without authentication, enabling full server compromise. A technical article link is provided for detailed analysis.

    0103285
    561 followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-26720 (CVSS: 9.8) Twenty CRM v1.15.0以前で、リモート攻撃者がlocal.driver.tsモジュールを通じて任意コード実行可能。影響: リモートコード実行。対策: バージョン更新。 https://maruomosquit.com/vulnerability/CVE-2026-26720/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-26720 is a high‑severity remote code execution flaw in Twenty CRM (v1.15.0 and earlier) via the local.driver.ts module; the advisory recommends updating to a newer version.

    00010393
    1.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26720 (CVSS:9.8, CRITICAL) is Analyzed. An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod..https://nvd.nist.gov/vuln/detail/CVE-2026-26720 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports analysis of CVE-2026-26720, a critical remote code execution vulnerability in Twenty CRM v1.15.0 and earlier, with CVSS 9.8, but does not mention PoCs, exploits, or patches.

    0000029
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26720 (CVSS:9.8, CRITICAL) is Analyzed. An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod..https://nvd.nist.gov/vuln/detail/CVE-2026-26720 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-26720 is a critical remote code execution vulnerability in Twenty CRM v1.15.0 and earlier, as documented on NVD, with no reported exploitation or patch information in the tweet.

    0000044
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26720 - Critical An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. https://www.thehackerwire.com/vulnerability/CVE-2026-26720/ https://t.co/GYD0gWip2u

    Post summary

    CVE-2026-26720 is a critical remote code execution vulnerability in Twenty CRM v1.15.0 and earlier, allowing attackers to execute arbitrary code via the local.driver.ts module.

    0000046
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptwentytwenty---

Explore more