CVE ID :CVE-2026-46624 Published : May 26, 2026, 6:16 p.m. | 2ย hours, 7ย minutes ago Description :Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS comm
PostgreSQL
Exploit
CVE-2026-46624
MITRE CVE High
Refer to CVE-2026-46624 NVD advisory