PT-2026-26446 · Suitecrm · Suitecrm

Jbince

·

Published

2026-03-19

·

Updated

2026-03-20

·

CVE-2026-29108

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 8.9.3
Description SuiteCRM is a customer relationship management software application. An authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and multi-factor authentication (MFA) configuration. Because any authenticated user can query this endpoint, it is possible to retrieve and potentially crack the passwords of administrative users. The vulnerable API endpoint allows unauthorized access to sensitive user data.
Recommendations Update to version 8.9.3 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-29108
GHSA-XC8W-XC9V-45W5

Affected Products

Suitecrm