Improper Authorization in SuiteCRM - CVE-2025-64489
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the Users module when handling requests from an inactive account with an existing authenticated session. A remote user can modify their own profile status field to escalate privileges.
Active sessions remain usable after the account is marked inactive.