SQL injection in SuiteCRM - CVE-2026-63215
Published: August 1, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to SQL injection in the REST API v4.1 get_entry_list method when handling crafted requests to /service/v4_1/rest.php. A remote user can send a specially crafted request to disclose sensitive information and modify data.
The issue is time-based blind and requires authenticated access.