Access Control Flaw in SuiteCRM Affects Multiple User Roles
CVE-2025-64490

8.3HIGH

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
8 November 2025

What is CVE-2025-64490?

SuiteCRM, a popular open-source CRM software, contains a vulnerability that allows low-privileged users to access and manipulate work items through the Resource Calendar and project screens, despite strict role management settings that are intended to restrict access. This issue arises from inconsistent enforcement of access control mechanisms across various modules, potentially leading to unauthorized exposure and alteration of sensitive data. The vulnerability is addressed in later versions, ensuring robust access control management.

Affected Version(s)

SuiteCRM < 7.14.8 < 7.14.8

SuiteCRM >= 8.0.0-beta.1, < 8.9.1 < 8.0.0-beta.1, 8.9.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64490 : Access Control Flaw in SuiteCRM Affects Multiple User Roles