Improper access control in SuiteCRM - CVE-2025-64490

 

Improper access control in SuiteCRM - CVE-2025-64490

Published: April 24, 2026


Vulnerability identifier: #VU127394
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64490
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass access controls and view and create restricted work items.

The vulnerability exists due to improper access control in the Resource Calendar, project screens, and cross-module role enforcement when handling requests to restricted modules and views. A remote user can access Resource Calendar and project functionality to bypass access controls and view and create restricted work items.

The issue affects modules and views that were explicitly set to disabled or none in role management.


Affected software

SuiteCRM

How to mitigate CVE-2025-64490

Install security update from vendor's website.

SuiteCRM - addressed in versions 7.14.8, 8.9.1

External References

Related Security Bulletins