CVE-2026-33288Disclosure(suitecrm / suitecrm)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch suitecrm suitecrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails to properly sanitize the user-supplied username before using it in a local database query. An attacker with valid, low-privilege directory credentials can exploit this to execute arbitrary SQL commands, leading to complete privilege escalation (e.g., logging in as the CRM Administrator). Versions 7.15.1 and 8.9.3 patch the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-20: 3Mentions · 2026-04-20: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-04-27: 103-2004-2004-27
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure2Patch1
2026-04-201
PoC1
2026-04-271
Disclosure1
Full discourse5 posts
  • kilserv@kilserv
    Disclosure

    Exemplo real: CVE-2026-33288, SQLi autenticada no SuiteCRM. CVSS base alto pelo impacto em integridade e confidencialidade. O vetor exige autenticação prévia, o q reduz a probabilidade de exploração. Risco real?

    Post summary

    The text discloses an authenticated SQL injection (CVE-2026-33288) in SuiteCRM with a high CVSS score, but offers no PoC, exploit, or patch details.

    10020198
    559 followersView on X
  • kilserv@kilserv
    PoC

    A vendor já aplicou os patches (CVE-2026-33288 e CVE-2026-33289). Pra quem curte code review e quer entender como a parada quebra por baixo dos panos, a PoC completinha no meu portfólio ou no medium: https://medium.com/@gui.mury.gm/from-code-analysis-to-cve-uncovering-sql-injection-in-churchcrm-cve-2025-67877-783c03863de9?postPublishedType=initial

    Post summary

    Patches were applied for CVE‑2026‑33288 and CVE‑2026‑33289, and a complete PoC for CVE‑2025‑67877 is shared via a Medium article.

    00011231
    561 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33288 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-33288

    Post summary

    The passage announces a SQL injection vulnerability (CVE-2026-33288) affecting older SuiteCRM releases, with no mention of PoC, exploits, active attacks, or fixes.

    00000114
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33288 - High SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the Suite... https://www.thehackerwire.com/vulnerability/CVE-2026-33288/ https://t.co/Rs8xQ5jNBB

    Post summary

    An SQL Injection vulnerability (CVE-2026-33288) in SuiteCRM prior to versions 7.15.1 and 8.9.3 is disclosed with a high severity rating.

    0000045
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33288: HIGH] Critical SQL Injection vulnerability in older SuiteCRM versions (pre-7.15.1, pre-8.9.3) allows for complete privilege escalation. Secure with the latest patches.#cve,CVE-2026-33288,#cybersecurity https://cvefind.com/CVE-2026-33288

    Post summary

    The post highlights a critical SQL Injection in older SuiteCRM versions and urges users to apply the latest patches to mitigate complete privilege escalation.

    0000044
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more