Cross-site scripting in SuiteCRM - CVE-2026-29100

 

Cross-site scripting in SuiteCRM - CVE-2026-29100

Published: April 24, 2026


Vulnerability identifier: #VU127405
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-29100
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary HTML content.

The vulnerability exists due to improper neutralization of input during web page generation in the login page when processing the default_user_name parameter. A remote attacker can supply a crafted parameter value to inject arbitrary HTML content.

User interaction is required to load the crafted login page, which may enable phishing attacks or page defacement.


Affected software

SuiteCRM

How to mitigate CVE-2026-29100

Install security update from vendor's website.

SuiteCRM - update to 7.15.1

External References

Related Security Bulletins