Security Advisory

CVE-2026-33288

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-19 23:08:11
Last updated 2026-03-20 18:09:17
Assigner GitHub_M
State PUBLISHED

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails to properly sanitize the user-supplied username before using it in a local database query. An attacker with valid, low-privilege directory credentials can exploit this to execute arbitrary SQL commands, leading to complete privilege escalation (e.g., logging in as the CRM Administrator). Versions 7.15.1 and 8.9.3 patch the issue.