SQL injection in SuiteCRM - CVE-2026-69136
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to SQL injection in the handleAttachments function when processing the remove_attachment POST parameter array. A remote user can send a specially crafted request to disclose sensitive information and modify data.
The issue can be exploited through the EmailTemplates Save endpoint, and no administrative rights are required.