CVE-2026-29103Disclosure(suitecrm / suitecrm)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch suitecrm suitecrm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a direct Patch Bypass of CVE-2024-49774. Although the vendor attempted to fix the issue in version 7.14.5, the underlying flaw in ModuleScanner.php regarding PHP token parsing remains. The scanner incorrectly resets its internal state ($checkFunction flag) when encountering any single-character token (such as =, ., or ;). This allows attackers to hide dangerous function calls (e.g., system(), exec()) using variable assignments or string concatenation, completely evading the MLP security controls. Versions 7.15.1 and 8.9.3 patch the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-358

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-19); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-19: 3Mentions · 2026-03-20: 2Mentions · 2026-05-13: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-20: 203-1903-2005-13
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure1General1Patch1
2026-03-202
Disclosure2
2026-05-131
General1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    General

    Four CVEs (CVE-2026-29103, CVE-2026-29104, CVE-2026-29892, CVE-2026-30441) shared the same root cause. An MCP server's response to the client includes free-form text fields — tool descriptions, resource summaries, prompt argument hints. These fields are surfaced into the…

    Post summary

    The snippet announces four related CVEs, noting a shared root cause involving free‑form text fields in MCP server responses, but does not include PoC, exploit details, or patch information.

    1000025
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29103 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists … https://www.cve.org/CVERecord?id=CVE-2026-29103 ----- Traducción: CVE-2026-29103 Sui… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑29103 for SuiteCRM, highlighting a critical RCE vulnerability and providing a link to the official CVE record.

    0000035
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29103 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists … https://www.cve.org/CVERecord?id=CVE-2026-29103

    Post summary

    The post announces a critical RCE vulnerability in SuiteCRM (CVE‑2026‑29103) and links to the official CVE record, but offers no proof‑of‑concept, exploit detail, or mitigation guidance.

    00000133
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29103: CRITICAL] Critical RCE vulnerability in SuiteCRM 7.15.0 & 8.9.2 allows admins to execute commands. Patch bypass of CVE-2024-49774. Issue partially resolved in 7.14.5. Update to 7.15.1/8.9.3 ...#cve,CVE-2026-29103,#cybersecurity https://cvefind.com/CVE-2026-29103

    Post summary

    The post announces CVE‑2026‑29103, a critical remote code execution flaw in SuiteCRM, and recommends updating to 7.15.1/8.9.3 (with 7.14.5 offering partial fixes) as the mitigative patch.

    0000063
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29103 - Critical SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 an... https://www.thehackerwire.com/vulnerability/CVE-2026-29103/ https://t.co/KiRt1Cfqqd

    Post summary

    The tweet announces the discovery of CVE-2026-29103, a critical RCE vulnerability in SuiteCRM 7.15.0, but does not provide PoC, exploit, patch, or active exploitation details.

    0000039
    137 followersView on X
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2026-29103: SuiteCRM Vulnerable to Remote Co... ModuleScanner.php token parsing logic fails hard - single chars like `=` reset $checkFunction flag, letting attackers c... https://zerodaysignal.com/vulnerability/CVE-2026-29103 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026‑29103, describing a token parsing flaw in SuiteCRM's ModuleScanner.php that could be abused, and provides a link for more details, but offers no PoC, exploit code, or patch information.

    0000054
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more