CVE-2026-29096 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 19, 2026
SuiteCRM - SQL Injection
Published: March 19, 2026Updated: March 19, 2026Remote Exploitable
Overview
SuiteCRM < 7.15.1 and < 8.9.3 contain a second-order SQL injection caused by unsanitized 'field_function' parameter in AOR_Reports module, letting authenticated users with Reports access extract database contents, exploit requires authentication with Reports access.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Authenticated users can extract sensitive database data and potentially achieve remote code execution on MySQL with FILE privilege.
Mitigation
Upgrade to versions 7.15.1 and 8.9.3 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-29096
- Severity
- High
- CVSS Score
- 8.1
- Type
- sql_injection
- Status
- new
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N