Broken Authentication in SuiteCRM iCal Service Allows Unauthorized Access
CVE-2025-54786

5.3MEDIUM

Key Information:

Vendor

Suitecrm

Vendor
CVE Published:
7 August 2025

What is CVE-2025-54786?

SuiteCRM, an open-source customer relationship management application, suffers from a broken authentication vulnerability in its legacy iCal service. This flaw is present in versions 7.14.6 and 8.8.0, allowing unauthenticated users to access sensitive meeting data related to any user by simply knowing their username. Additionally, the vulnerability can facilitate user enumeration, posing significant risks to user privacy and security. The issues have been addressed in version 7.14.7 and 8.8.1, highlighting the importance of updating to mitigate these risks.

Affected Version(s)

SuiteCRM-Core >= 8.8.0, < 8.8.1 < 8.8.0, 8.8.1

SuiteCRM-Core >= 7.14.6, < 7.14.7 < 7.14.6, 7.14.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-54786 : Broken Authentication in SuiteCRM iCal Service Allows Unauthorized Access