Server-Side Request Forgery in SuiteCRM PDF Management
CVE-2026-29107
5MEDIUM
What is CVE-2026-29107?
An issue has been identified in SuiteCRM that allows an attacker to exploit the creation of PDF templates with <img> tags. When a PDF is generated using these templates, it can lead to Server-Side Request Forgery, permitting unauthorized requests from the server. This vulnerability affects versions prior to 7.15.1 and 8.9.3, which have since been patched to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM < 7.15.1 < 7.15.1
SuiteCRM >= 8.0.0, < 8.9.3 < 8.0.0, 8.9.3
