PT-2026-26447 · Suitecrm · Suitecrm-Core
Rvizx
·
Published
2026-03-19
·
Updated
2026-03-20
·
CVE-2026-29109
CVSS v4.0
8.6
High
| AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator to execute arbitrary system commands on the server.
FilterDefinitionProvider.php calls unserialize() on user-controlled data from the saved search.contents database column without restricting instantiable classes. Version 8.9.3 patches the issue.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suitecrm-Core