Broken Authentication in SuiteCRM iCal Service Allows Unauthorized Access
CVE-2025-54786
What is CVE-2025-54786?
SuiteCRM, an open-source customer relationship management application, suffers from a broken authentication vulnerability in its legacy iCal service. This flaw is present in versions 7.14.6 and 8.8.0, allowing unauthenticated users to access sensitive meeting data related to any user by simply knowing their username. Additionally, the vulnerability can facilitate user enumeration, posing significant risks to user privacy and security. The issues have been addressed in version 7.14.7 and 8.8.1, highlighting the importance of updating to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM-Core >= 8.8.0, < 8.8.1 < 8.8.0, 8.8.1
SuiteCRM-Core >= 7.14.6, < 7.14.7 < 7.14.6, 7.14.7
References
CVSS V3.1
Timeline
Vulnerability published
