CVE-2026-29096 is a second-order SQL injection vulnerability affecting SuiteCRM versions prior to 7.15.1 and 8.9.3. An authenticated user with Reports access can inject malicious SQL via the `field_function` parameter, which is later executed without sanitization when a report is viewed. This medium-severity vulnerability (CVSS 6.5) allows for the extraction of arbitrary database contents, including sensitive data like password hashes and API tokens. Under specific conditions (MySQL with FILE privilege), this could lead to Remote Code Execution. There is currently no evidence of active exploitation, public exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.15.1CPE matchmatch criteria | cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.9.3CPE matchmatch criteria | cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.