CVE-2026-26720: Code Injection
Published Mar 2, 2026
·Updated
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
Affected Software
2 affected components
Twenty Twenty CRM<=1.15.0
Twenty Twenty<=1.15.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26720?
CVE-2026-26720 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2026-26720?
To fix CVE-2026-26720, update Twenty CRM to version 1.15.1 or later, which addresses this vulnerability.
3
Who is affected by CVE-2026-26720?
Users of Twenty CRM version 1.15.0 and earlier are affected by CVE-2026-26720.
4
What impact does CVE-2026-26720 have?
CVE-2026-26720 allows remote attackers to execute arbitrary code on the affected system.
5
When was CVE-2026-26720 publicly disclosed?
CVE-2026-26720 was publicly disclosed in early 2026.