CVE-2026-33288
HIGHSuiteCRM has Authenticated SQL Injection in Authentication Module
Title source: cnaDescription
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails to properly sanitize the user-supplied username before using it in a local database query. An attacker with valid, low-privilege directory credentials can exploit this to execute arbitrary SQL commands, leading to complete privilege escalation (e.g., logging in as the CRM Administrator). Versions 7.15.1 and 8.9.3 patch the issue.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-7g39-m4fg-vrq7
X_Refsource_Misc x_refsource_misc
https://docs.suitecrm.com/admin/releases/7.15.x
Scores
CVSS v3
8.8
EPSS
0.0044
EPSS Percentile
35.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (3)
suitecrm/suitecrm
< 7.15.1
SuiteCRM/SuiteCRM
< 7.15.1
SuiteCRM/SuiteCRM
>= 8.0.0, < 8.9.3
Published
Mar 20, 2026
Tracked Since
Mar 20, 2026