SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and manipulate data they should not have permission to interact with. Versions 7.15.1 and 8.9.3 patch the issue.
References
| Link | Resource |
|---|---|
| https://docs.suitecrm.com/admin/releases/7.15.x | Release Notes |
| https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-m6x8-3hxp-qxwv | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-20 00:16
Updated : 2026-03-23 16:46
NVD link : CVE-2026-29189
Mitre link : CVE-2026-29189
CVE.ORG link : CVE-2026-29189
JSON object : View
Products Affected
suitecrm
- suitecrm
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
