CVE-2026-46624Disclosure(twenty / twenty)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the database server by injecting SQL through the unsanitized timeZone parameter in the REST API groupBy endpoint. The timeZone field within the group_by query parameter is directly interpolated into a raw SQL expression using JavaScript template literals without any parameterization, validation, or escaping. This affects engine/api/graphql/graphql-query-runner/group-by/resolvers/utils/get-group-by-expression.util.ts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twenty

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
twenty

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-26: 2Mentions · 2026-05-27: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 105-2605-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-262
Disclosure2
2026-05-271
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Twenty CRM, Remote Code Execution, #CVE-2026-46624 (critical) https://dailycve.com/twenty-crm-remote-code-execution-cve-2026-46624-critical/

    Post summary

    A new critical remote code execution vulnerability (CVE‑2026‑46624) affecting Twenty CRM has been disclosed, with basic technical details provided but no PoC, exploit, or patch information in the text.

    0000049
    207 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46624 Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and Pos… https://www.cve.org/CVERecord?id=CVE-2026-46624 ----- Traducción: CVE-2026-46624 Twe… http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑46624, a critical RCE in the open‑source CRM Twenty caused by chained SQL injection, but offers no PoC, exploit code, active exploitation reports, or patch details.

    0000056
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46624 Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and Pos… https://www.cve.org/CVERecord?id=CVE-2026-46624

    Post summary

    The text announces CVE‑2026‑46624, detailing a critical RCE via chained SQL injection in specific versions of the open-source CRM Twenty, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000197
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptwentytwenty---

Explore more