PT-2026-26448 · Suitecrm · Suitecrm

Anderson7

+1

·

Publicado

2026-03-19

·

Atualizado

2026-03-20

·

CVE-2026-29189

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.15.1 SuiteCRM versions prior to 8.9.3
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Before versions 7.15.1 and 8.9.3, the REST API V8 lacks Access Control List (ACL) checks on several endpoints. This allows authenticated users to access and manipulate data they are not permitted to interact with. The API endpoints are affected. The vulnerable parameters or variables are not specified.
Recommendations Update to SuiteCRM version 7.15.1 or later. Update to SuiteCRM version 8.9.3 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29189
GHSA-M6X8-3HXP-QXWV

Produtos afetados

Suitecrm