Arbitrary file upload in SuiteCRM - CVE-2026-29104

 

Arbitrary file upload in SuiteCRM - CVE-2026-29104

Published: April 24, 2026


Vulnerability identifier: #VU127410
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29104
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to upload arbitrary files.

The vulnerability exists due to unrestricted upload of file with dangerous type in the Configurator addfontresult view when uploading PDF font files. A remote privileged user can upload a file with an attacker-controlled filename to upload arbitrary files.

The upload directory is not directly web-accessible by default, but the issue breaks security boundaries and may enable further attacks in certain deployment configurations or when combined with other vulnerabilities.


Affected software

SuiteCRM

How to mitigate CVE-2026-29104

Install security update from vendor's website.

SuiteCRM - addressed in versions 7.15.1, 8.9.3

External References

Related Security Bulletins