Path traversal in SuiteCRM - CVE-2026-63213
Published: August 1, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to write arbitrary files and execute arbitrary code.
The vulnerability exists due to path traversal in the Upgrade Wizard commit flow when processing a tampered final install request containing the hidden zip_to_dir parameter. A remote privileged user can modify the zip_to_dir parameter to copy extracted package files to an attacker-chosen path outside the intended upgrade destination to write arbitrary files and execute arbitrary code.
The issue is limited to the Upgrade Wizard commit phase and can also be used to overwrite application files or corrupt configuration and code files.