Cross-site scripting in SuiteCRM - CVE-2026-29106
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the return_id parameter when handling requests that copy the parameter value into an HTML event handler attribute. A remote privileged user can send a specially crafted request to execute arbitrary script in a victim's browser.
User interaction is required for the victim to load the malicious content.