Missing Authorization Flaw in SuiteCRM Affects User Role Access
CVE-2026-108712

5.3MEDIUM

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108712?

SuiteCRM versions 7.15.2 and 8.10.2 exhibit a critical flaw in the DetailUserRole entry point, which allows authenticated non-admin users to access another user's access control list (ACL) data. By manipulating the record parameter, an attacker can specify the ID of another non-admin user, thereby exposing that user's assigned roles and their per-module ACL action matrix. This vulnerability poses a significant threat to user confidentiality and data integrity within the application.

Affected Version(s)

SuiteCRM 0 <= 7.15.2

SuiteCRM 8.0.0 <= 8.10.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.