Arbitrary file upload in SuiteCRM - CVE-2026-29104
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to upload arbitrary files.
The vulnerability exists due to unrestricted upload of file with dangerous type in the Configurator addfontresult view when uploading PDF font files. A remote privileged user can upload a file with an attacker-controlled filename to upload arbitrary files.
The upload directory is not directly web-accessible by default, but the issue breaks security boundaries and may enable further attacks in certain deployment configurations or when combined with other vulnerabilities.