PT-2026-26446 · Suitecrm · Suitecrm

Jbince

·

Publicado

2026-03-19

·

Atualizado

2026-03-20

·

CVE-2026-29108

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 8.9.3
Description SuiteCRM is a customer relationship management software application. An authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and multi-factor authentication (MFA) configuration. Because any authenticated user can query this endpoint, it is possible to retrieve and potentially crack the passwords of administrative users. The vulnerable API endpoint allows unauthorized access to sensitive user data.
Recommendations Update to version 8.9.3 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29108
GHSA-XC8W-XC9V-45W5

Produtos afetados

Suitecrm