Authorization bypass through user-controlled key in SuiteCRM - CVE-2026-63217
Published: August 1, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in the generatePdf entry point when loading records by user-supplied identifiers. A remote user can request a record they are not authorized to access to disclose sensitive information.
The issue bypasses role-based access control for data reads and can expose all field values from records across any module, including custom fields.