CVE Explorer
CVE-2026-29104
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can bypass intended file type restrictions when uploading PDF font files, allowing arbitrary files with attacker‑controlled filenames to be written to the server. Although the upload directory is not directly web‑accessible by d
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"SuiteCRM","vendor":"SuiteCRM","versions":[{"status":"affected","version":"< 7.15.1"},{"status":"affected","version":">= 8.0.0, < 8.9.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:14906138c47280d8e0fbd7baddb46bafe090cb158c1e9c5c27a1e3e4339b195b · sha256:2b3f01528b9919cf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:14906138c47280d8e0fbd7baddb46bafe090cb158c1e9c5c27a1e3e4339b195b · sha256:2b3f01528b9919cf… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:14906138c47280d8e0fbd7baddb46bafe090cb158c1e9c5c27a1e3e4339b195b · sha256:2b3f01528b9919cf… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://docs.suitecrm.com/admin/releases/7.15.x","tags":["x_refsource_MISC"],"url":"https://docs.suitecrm.com/admin/releases/7.15.x"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14906138c47280d8e0fbd7baddb46bafe090cb158c1e9c5c27a1e3e4339b195b · sha256:2b3f01528b9919cf… · /containers/cna/references/1
{"name":"https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5hx9-cmmx-26p3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5hx9-cmmx-26p3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14906138c47280d8e0fbd7baddb46bafe090cb158c1e9c5c27a1e3e4339b195b · sha256:2b3f01528b9919cf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.