CVE-2026-108712
Received Received - Intake

Missing Authorization in SuiteCRM Exposes User ACL Data

Vulnerability report for CVE-2026-108712, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

SuiteCRM through 7.15.2 and 8.10.2 contains a missing authorization vulnerability in the DetailUserRole entry point that allows authenticated non-admin users to view other users' ACL data. Attackers can supply another non-admin user's id in the record parameter to read that user's assigned roles and per-module ACL action matrix.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
SuiteCRM SuiteCRM 0
SuiteCRM SuiteCRM 8.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SuiteCRM versions through 7.15.2 and 8.10.2 have a missing authorization flaw in the DetailUserRole entry point. Authenticated non-admin users can exploit this to view other users' ACL (Access Control List) data by supplying another user's ID in the record parameter. This exposes assigned roles and per-module permissions.

Detection Guidance

To detect this vulnerability, check SuiteCRM logs for unauthorized access attempts to the DetailUserRole entry point. Look for requests with a 'record' parameter containing another user's ID. Verify if non-admin users can access ACL data for other users by manually testing the endpoint with a non-admin account and another user's ID in the 'record' parameter.

Impact Analysis

An attacker with non-admin access could read sensitive user role assignments and permissions. This may allow privilege escalation, unauthorized data access, or lateral movement within the system. The impact depends on the exposed permissions but could compromise confidentiality and integrity of user data.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data access controls or HIPAA by revealing user permissions in healthcare systems. Non-compliance may result from unauthorized data exposure, lack of proper access controls, or failure to protect sensitive user information as required by these regulations.

Mitigation Strategies

Update SuiteCRM to version 7.15.3 or 8.10.3 or later to address the missing authorization vulnerability in the DetailUserRole entry point.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108712. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart