CVE-2026-29096Disclosure(suitecrm / suitecrm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR_Reports module), the `field_function` parameter from POST data is saved directly into the `aor_fields` table without any validation. Later, when the report is executed/viewed, this value is concatenated directly into a SQL SELECT query without sanitization, enabling second-order SQL injection. Any authenticated user with Reports access can extract arbitrary database contents (password hashes, API tokens, config values). On MySQL with FILE privilege, this could lead to RCE via SELECT INTO OUTFILE. Versions 7.15.1 and 8.9.3 patch the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-25: 1Technical Details · 2026-03-19: 103-1903-2003-25
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-202
Disclosure2
2026-03-251
General1
Full discourse4 posts
  • 秋风@q1uf3ng
    General

    What are the limits of AI-assisted vulnerability hunting? I obtained 23 CVEs in one month. BentoML 8.2k CVE-2026-27905 HIGH SillyTavern 24.6k CVE-2026-26286 HIGH Plane 28.2k CVE-2026-27705 MEDIUM NocoDB 46.4k CVE-2026-28399 MEDIUM Mautic 8.4k CVE-2026-3105 HIGH File Browser 27.9k CVE-2026-28492 HIGH OpenReplay 7.3k CVE-2026-28443 MEDIUM SuiteCRM 4.0k CVE-2026-29096 HIGH Pimcore 3.6k CVE-2026-27461 HIGH Craft CMS 5.2k CVE-2026-32263 MEDIUM Froxlor 1.6k CVE-2026-30932 HIGH Actual Budget 3.2k CVE-2026-27638 HIGH Lemmy 14.0k CVE-2026-29178 MEDIUM Chartbrew 2.6k CVE-2026-27005 HIGH Tautulli 1.7k CVE-2026-28505 HIGH Typebot 9.5k CVE-2026-33712 CRITICAL LibreChat 34.7k CVE-2026-31942 HIGH Coolify 33.8k CVE-2026-27883 HIGH Gotenberg 3.0k CVE-2026-27018 HIGH Unkey 5.2k CVE-2026-28339 MEDIUM Piwigo 3.3k CVE-2026-27634 CRITICAL Pixelfed 10.7k CVE-2026-27011 HIGH Follow (Folo) 3.0k CVE-2026-27499 HIGH

    Post summary

    The post lists newly discovered CVEs with their severities but provides no additional context such as proofs of concept, exploitation evidence, patches, or technical details.

    720220514825.9K
    1.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29096 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing… https://www.cve.org/CVERecord?id=CVE-2026-29096 ----- Traducción: CVE-2026-29096 Sui… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑29096 for SuiteCRM, noting affected versions and linking to the CVE record for further details.

    0000037
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29096 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing… https://www.cve.org/CVERecord?id=CVE-2026-29096

    Post summary

    The post briefly announces a CVE affecting SuiteCRM versions prior to 7.15.1 and 8.9.3, noting the issue occurs during create or edit operations.

    00000179
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-29096 - High SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR_Reports mo... https://www.thehackerwire.com/vulnerability/CVE-2026-29096/ https://t.co/lH0lTxbn7i

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑29096) affecting SuiteCRM versions before 7.15.1 and 8.9.3, detailing the flaw’s context but providing no PoC, exploit, or patch information.

    0000042
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more