Missing Authorization Vulnerability in SuiteCRM by SalesAgility
CVE-2026-108713

5.3MEDIUM

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108713?

SuiteCRM versions 7.15.2 and 8.x through 8.10.2 are susceptible to a missing authorization flaw that permits authenticated users, even with low privileges, to create and modify EmailMarketing records. This vulnerability arises when users without access to campaigns can exploit the setCampaignMarketingAndTemplate entry point by posting marketingId, campaignId, and templateId, allowing them to reattach marketing messages or change the template used in campaign emails. This could lead to unauthorized alterations in email marketing strategies, compromising the integrity of the campaign management process.

Affected Version(s)

SuiteCRM 0 <= 7.15.2

SuiteCRM 8.0.0 <= 8.10.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.