CVE-2026-29104Disclosure(suitecrm / suitecrm)

MEDIUMCVSS 2.7 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch suitecrm suitecrm systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can bypass intended file type restrictions when uploading PDF font files, allowing arbitrary files with attacker‑controlled filenames to be written to the server. Although the upload directory is not directly web‑accessible by default, this behavior breaks security boundaries and may enable further attacks when combined with other vulnerabilities or in certain deployment configurations. Versions 7.15.1 and 8.9.3 patch the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-04-15: 1Mentions · 2026-05-13: 1Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-05-13: 103-2004-1505-13
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1General1
2026-04-151
Active Exploitation1
2026-05-131
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Four CVEs (CVE-2026-29103, CVE-2026-29104, CVE-2026-29892, CVE-2026-30441) shared the same root cause. An MCP server's response to the client includes free-form text fields — tool descriptions, resource summaries, prompt argument hints. These fields are surfaced into the…

    Post summary

    The text announces that four related CVEs share the same root cause involving free‑form text fields in MCP server responses, providing initial technical details of the vulnerabilities.

    1000025
    210 followersView on X
  • Solomon Neas@solomonneas
    Active Exploitation

    🔴 SharePoint CVE-2026-32115 is under active exploitation. Patch now. 🔴 Marimo CVE-2026-29104 targets exposed notebooks for cloud credential theft. 🟡 108 malicious Chrome extensions stole Google and Telegram data. http://solomonneas.dev/intel

    Post summary

    The post warns that SharePoint CVE‑2026‑32115 and Marimo CVE‑2026‑29104 are being actively exploited and urges immediate patching, but it offers no specific technical details or PoC.

    00000234
    32 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29104 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an aut… https://www.cve.org/CVERecord?id=CVE-2026-29104 ----- Traducción: CVE-2026-29104 Sui… http://infoflow.cloud`

    Post summary

    A new CVE-2026-29104 affecting SuiteCRM versions prior to 7.15.1 and 8.9.3 is announced, with a link to the CVE record, but no exploit details or mitigation information are provided.

    0000028
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29104 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an aut… https://www.cve.org/CVERecord?id=CVE-2026-29104

    Post summary

    The post briefly references CVE-2026-29104 for SuiteCRM, linking to the CVE record but providing no additional details or evidence of exploitation, patches, or technical specifics.

    00000130
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more