SQL injection in SuiteCRM - CVE-2026-69141
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the action_get_kb_articles action in modules/Cases/controller.php when processing the search parameter in POST requests. A remote user can send a specially crafted search parameter to disclose sensitive information.
The issue can be exploited for time-based blind SQL injection, and access to the Cases module is required.