PT-2026-26449 · Suitecrm · Suitecrm

Anderson7

+1

·

Published

2026-03-19

·

Updated

2026-03-20

·

CVE-2026-32697

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 8.9.3
Description SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.9.3, the RecordHandler::getRecord() method retrieves records based on module and ID without verifying the current user’s access permissions for viewing. The saveRecord() method correctly checks access permissions for saving, but getRecord() bypasses the equivalent check for viewing. This could allow unauthorized access to sensitive information.
Recommendations Update to version 8.9.3 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-32697
GHSA-9P9G-224X-6RMM

Affected Products

Suitecrm