PT-2026-26449 · Suitecrm · Suitecrm

Anderson7

+1

·

Publicado

2026-03-19

·

Atualizado

2026-03-20

·

CVE-2026-32697

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 8.9.3
Description SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.9.3, the RecordHandler::getRecord() method retrieves records based on module and ID without verifying the current user’s access permissions for viewing. The saveRecord() method correctly checks access permissions for saving, but getRecord() bypasses the equivalent check for viewing. This could allow unauthorized access to sensitive information.
Recommendations Update to version 8.9.3 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32697
GHSA-9P9G-224X-6RMM

Produtos afetados

Suitecrm