CVE-2026-29102

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-19 23:16

Updated : 2026-03-24 14:29


NVD link : CVE-2026-29102

Mitre link : CVE-2026-29102

CVE.ORG link : CVE-2026-29102


JSON object : View

Products Affected

suitecrm

  • suitecrm
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')