Remote Code Execution Vulnerability in SuiteCRM by SuiteCRM
CVE-2026-29103

9.1CRITICAL

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
19 March 2026

What is CVE-2026-29103?

SuiteCRM, the open-source customer relationship management software, has a Remote Code Execution vulnerability that affects versions 7.15.0 and 8.9.2. This flaw allows authenticated administrators to execute arbitrary system commands due to a Patch Bypass of a previously identified vulnerability. The issue lies in the incorrect parsing of PHP tokens in the ModuleScanner.php file, specifically how it resets its state when encountering single-character tokens. Attackers can exploit this flaw to circumvent security controls by masking dangerous functions with variable assignments or string concatenation. Users are urged to upgrade to versions 7.15.1 or 8.9.3 to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SuiteCRM < 7.15.1 < 7.15.1

SuiteCRM >= 8.0.0, < 8.9.3 < 8.0.0, 8.9.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.