Authentication Bypass Vulnerability in SuiteCRM by SalesAgility
CVE-2026-29108
6.5MEDIUM
What is CVE-2026-29108?
SuiteCRM, an open-source CRM software by SalesAgility, suffers from an authentication bypass vulnerability affecting versions prior to 8.9.3. This flaw resides within an authenticated API endpoint that allows any logged-in user to access detailed sensitive information of other users, including password hashes, usernames, and multi-factor authentication configurations. Such exposure enables malicious actors to compromise legitimate user accounts, including administrative privileges. The issue has been resolved in version 8.9.3, and users are strongly advised to update to safeguard their systems.
Affected Version(s)
SuiteCRM-Core < 8.9.3
