Missing Authorization Vulnerability in SuiteCRM by SalesAgility
CVE-2026-108713
5.3MEDIUM
What is CVE-2026-108713?
SuiteCRM versions 7.15.2 and 8.x through 8.10.2 are susceptible to a missing authorization flaw that permits authenticated users, even with low privileges, to create and modify EmailMarketing records. This vulnerability arises when users without access to campaigns can exploit the setCampaignMarketingAndTemplate entry point by posting marketingId, campaignId, and templateId, allowing them to reattach marketing messages or change the template used in campaign emails. This could lead to unauthorized alterations in email marketing strategies, compromising the integrity of the campaign management process.
Affected Version(s)
SuiteCRM 0 <= 7.15.2
SuiteCRM 8.0.0 <= 8.10.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
