CVE-2026-29189

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and manipulate data they should not have permission to interact with. Versions 7.15.1 and 8.9.3 patch the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*

History

23 Mar 2026, 16:46

Type Values Removed Values Added
Summary
  • (es) SuiteCRM es una aplicación de software de gestión de relaciones con clientes (CRM) de código abierto y lista para empresas. Antes de las versiones 7.15.1 y 8.9.3, la API REST V8 de SuiteCRM carece de comprobaciones de ACL (Lista de Control de Acceso) en varios puntos finales, lo que permite a los usuarios autenticados acceder y manipular datos con los que no deberían tener permiso para interactuar. Las versiones 7.15.1 y 8.9.3 parchean el problema.
References () https://docs.suitecrm.com/admin/releases/7.15.x - () https://docs.suitecrm.com/admin/releases/7.15.x - Release Notes
References () https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-m6x8-3hxp-qxwv - () https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-m6x8-3hxp-qxwv - Vendor Advisory
First Time Suitecrm
Suitecrm suitecrm
CPE cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*

20 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 00:16

Updated : 2026-03-23 16:46


NVD link : CVE-2026-29189

Mitre link : CVE-2026-29189

CVE.ORG link : CVE-2026-29189


JSON object : View

Products Affected

suitecrm

  • suitecrm
CWE
CWE-639

Authorization Bypass Through User-Controlled Key