LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-29096

CVE-2026-29096 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 19, 2026

SuiteCRM - SQL Injection

Published: March 19, 2026Updated: March 19, 2026Remote Exploitable

Overview

SuiteCRM < 7.15.1 and < 8.9.3 contain a second-order SQL injection caused by unsanitized 'field_function' parameter in AOR_Reports module, letting authenticated users with Reports access extract database contents, exploit requires authentication with Reports access.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Authenticated users can extract sensitive database data and potentially achieve remote code execution on MySQL with FILE privilege.

Mitigation

Upgrade to versions 7.15.1 and 8.9.3 or later.

Details

CVE ID
CVE-2026-29096
Severity
High
CVSS Score
8.1
Type
sql_injection
Status
new

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N