CVE-2026-33289Disclosure(suitecrm / suitecrm)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch suitecrm suitecrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied input before embedding it into the LDAP search filter. By injecting LDAP control characters, an unauthenticated attacker can manipulate the query logic, which can lead to authentication bypass or information disclosure. Versions 7.15.1 and 8.9.3 patch the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-04-20: 103-2004-20
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure3
2026-04-201
PoC1
Full discourse4 posts
  • kilserv@kilserv
    PoC

    A vendor já aplicou os patches (CVE-2026-33288 e CVE-2026-33289). Pra quem curte code review e quer entender como a parada quebra por baixo dos panos, a PoC completinha no meu portfólio ou no medium: https://medium.com/@gui.mury.gm/from-code-analysis-to-cve-uncovering-sql-injection-in-churchcrm-cve-2025-67877-783c03863de9?postPublishedType=initial

    Post summary

    The vendor reported patching CVE‑2026‑33288/33289, while a full Proof of Concept for a related SQL injection is shared via a Medium article.

    00011231
    561 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33289 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulner… https://www.cve.org/CVERecord?id=CVE-2026-33289

    Post summary

    The post announces an LDAP Injection flaw in SuiteCRM affecting versions prior to 7.15.1 and 8.9.3, linking to the CVE record but offering no proof‑of‑concept, exploit, or patch details.

    00000112
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33289 - High SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the Sui... https://www.thehackerwire.com/vulnerability/CVE-2026-33289/ https://t.co/fnFhabBAmM

    Post summary

    The post announces CVE‑2026‑33289 as a high‑severity LDAP injection vulnerability in SuiteCRM versions earlier than 7.15.1 and 8.9.3, with no evidence of PoC, exploit code, or active exploitation.

    0000049
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33289: HIGH] Critical LDAP Injection vulnerability discovered in open-source SuiteCRM versions prior to 7.15.1 and 8.9.3. Attackers can exploit this flaw to bypass authentication or disclose sensit...#cve,CVE-2026-33289,#cybersecurity https://cvefind.com/CVE-2026-33289

    Post summary

    The post announces a high‑severity LDAP injection vulnerability in SuiteCRM versions before 7.15.1 and 8.9.3, capable of bypassing authentication and disclosing sensitive information.

    0000050
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more