CVE-2026-108713
Received Received - Intake

Authenticated Users Can Modify EmailMarketing Records in SuiteCRM

Vulnerability report for CVE-2026-108713, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

SuiteCRM through 7.15.2 and 8.x through 8.10.2 contains a missing authorization vulnerability that allows authenticated users to create and modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Low-privileged users denied Campaigns access can post marketingId, campaignId, and templateId to reattach marketing messages or swap the template EmailMan sends in campaign emails.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
SuiteCRM SuiteCRM 0
SuiteCRM SuiteCRM 8.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SuiteCRM versions through 7.15.2 and 8.x through 8.10.2 have a missing authorization vulnerability. Authenticated users can create or modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Low-privileged users who are denied Campaigns access can still post marketingId, campaignId, and templateId to reattach marketing messages or change the template used in campaign emails.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized EmailMarketing record modifications in SuiteCRM. Review application logs for POST requests to the setCampaignMarketingAndTemplate entry point by low-privileged users. Inspect database tables for unexpected changes to marketingId, campaignId, or templateId fields.

Impact Analysis

An attacker with low privileges could modify email marketing campaigns, potentially sending unauthorized messages or altering templates. This could lead to misinformation, phishing risks, or reputational damage if abused.

Compliance Impact

This vulnerability could lead to unauthorized data processing or communication, violating GDPR's principles of lawfulness and transparency. For HIPAA, it may risk exposing protected health information if email campaigns are tampered with.

Mitigation Strategies

Upgrade SuiteCRM to the latest patched version (7.15.3 or 8.10.3+). Apply strict access controls to prevent low-privileged users from modifying EmailMarketing records. Monitor and audit all changes to marketing campaigns and templates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart