CVE-2025-54786

Source
https://cve.org/CVERecord?id=CVE-2025-54786
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54786.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54786
Aliases
Published
2025-08-06T23:23:00Z
Modified
2026-08-27T03:57:08Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data
Details

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-284",
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54786.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.14.6"
                },
                {
                    "fixed": "7.14.7"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/SuiteCRM/SuiteCRM

Affected ranges

Type
GIT
Repo
https://github.com/SuiteCRM/SuiteCRM
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:salesagility:suitecrm:7.14.6:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.14.6"
        },
        {
            "last_affected": "7.14.6"
        }
    ],
    "source": "CPE_STRING"
}
Type
GIT
Repo
https://github.com/suitecrm/suitecrm-core
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:salesagility:suitecrm:8.8.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.8.0"
        },
        {
            "fixed": "8.8.1"
        },
        {
            "last_affected": "8.8.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

7.*
7.14.6
8.*
8.8.0
v7.*
v7.14.6
v8.*
v8.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54786.json"