PT-2026-26447 · Suitecrm · Suitecrm
Rvizx
·
Published
2026-03-19
·
Updated
2026-03-20
·
CVE-2026-29109
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SuiteCRM versions prior to 8.9.3
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization issue in the SavedSearch filter processing component. This allows an authenticated administrator to execute arbitrary system commands on the server. The
FilterDefinitionProvider.php file calls the unserialize() function on user-controlled data from the saved search.contents database column without restricting instantiable classes.Recommendations
Update to SuiteCRM version 8.9.3 or later.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suitecrm