SQL injection in SuiteCRM - CVE-2026-69136

 

SQL injection in SuiteCRM - CVE-2026-69136

Published: August 6, 2026


Vulnerability identifier: #VU141076
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69136
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data.

The vulnerability exists due to SQL injection in the handleAttachments function when processing the remove_attachment POST parameter array. A remote user can send a specially crafted request to disclose sensitive information and modify data.

The issue can be exploited through the EmailTemplates Save endpoint, and no administrative rights are required.


Affected software

SuiteCRM

How to mitigate CVE-2026-69136

Install security update from vendor's website.

SuiteCRM - addressed in versions 7.15.2, 8.10.2

External References

Related Security Bulletins