CVE-2026-46624
Critical Remote Code Execution (RCE) vulnerability in Twenty CRM (versions 1.7.7–1.16.7) allows authenticated users to execute arbitrary OS commands via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. Exploits require the PostgreSQL user to have super user privileges. CWE-78 and CWE-89.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Twenty CRM users running versions 1.7.7 through 1.16.7
Real-world impact
Attackers could gain full control of the database server, leading to data theft, system compromise, or service disruption.
Why this severity
CVSS 9.9 (critical): High confidence in exploitation, high impact on confidentiality, integrity, and availability.
What to do about it
- ›Restrict the PostgreSQL user to non-super user privileges to prevent arbitrary command execution.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description states vulnerability exists in versions 1.7.7–1.16.7; no official fix documented in provided sources.
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/twentyhq/twenty/security/ad…exploitvendor advisory