Unsafe Deserialization Vulnerability in SuiteCRM by SuiteCRM
CVE-2026-29109
8.6HIGH
What is CVE-2026-29109?
SuiteCRM, an enterprise-ready open-source Customer Relationship Management platform, suffers from an unsafe deserialization vulnerability in its SavedSearch filter processing component. This flaw allows authenticated administrators to execute arbitrary system commands through user-controlled data in the saved_search.contents database column. The vulnerability lies in the misuse of the unserialize() function within FilterDefinitionProvider.php, which does not impose restrictions on instantiable classes. SuiteCRM has addressed this issue in version 8.9.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM-Core < 8.9.3
