Missing Authorization Flaw in SuiteCRM Affects User Role Access
CVE-2026-108712
5.3MEDIUM
What is CVE-2026-108712?
SuiteCRM versions 7.15.2 and 8.10.2 exhibit a critical flaw in the DetailUserRole entry point, which allows authenticated non-admin users to access another user's access control list (ACL) data. By manipulating the record parameter, an attacker can specify the ID of another non-admin user, thereby exposing that user's assigned roles and their per-module ACL action matrix. This vulnerability poses a significant threat to user confidentiality and data integrity within the application.
Affected Version(s)
SuiteCRM 0 <= 7.15.2
SuiteCRM 8.0.0 <= 8.10.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
