SQL injection in SuiteCRM - CVE-2026-69135
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to sql injection in the Project module Save.php endpoint when processing the duplicateId POST parameter. A remote user can send a specially crafted request to disclose sensitive information.
The issue can be exploited through blind time-based SQL injection.