Authentication Bypass Vulnerability in SuiteCRM by SalesAgility
CVE-2026-29108
What is CVE-2026-29108?
SuiteCRM, an open-source CRM software by SalesAgility, suffers from an authentication bypass vulnerability affecting versions prior to 8.9.3. This flaw resides within an authenticated API endpoint that allows any logged-in user to access detailed sensitive information of other users, including password hashes, usernames, and multi-factor authentication configurations. Such exposure enables malicious actors to compromise legitimate user accounts, including administrative privileges. The issue has been resolved in version 8.9.3, and users are strongly advised to update to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM-Core < 8.9.3
