CVE-2026-29109

Source
https://cve.org/CVERecord?id=CVE-2026-29109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-29109
Aliases
  • GHSA-mhq2-277m-6w24
Published
2026-03-19T23:12:11.526Z
Modified
2026-08-12T03:51:30.441562378Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Processing
Details

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator to execute arbitrary system commands on the server. FilterDefinitionProvider.php calls unserialize() on user-controlled data from the saved_search.contents database column without restricting instantiable classes. Version 8.9.3 patches the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29109.json",
    "cwe_ids": [
        "CWE-502"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/suitecrm/suitecrm-core

Affected ranges

Type
GIT
Repo
https://github.com/suitecrm/suitecrm-core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.9.3"
        }
    ]
}

Affected versions

v8.*
v8.0.0
v8.0.0-beta.1
v8.0.0-beta.2
v8.0.0-beta.3
v8.0.0-rc
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.1.0
v8.1.1
v8.1.2
v8.1.3
v8.2.0
v8.2.0-beta.2
v8.2.1
v8.2.2
v8.2.3
v8.2.4
v8.3.0
v8.3.1
v8.4.0
v8.4.0-beta
v8.4.1
v8.4.2
v8.5.0
v8.5.1
v8.6.0
v8.6.1
v8.6.2
v8.7.0
v8.7.0-beta
v8.7.1
v8.8.0
v8.8.0-beta
v8.8.1
v8.9.0
v8.9.1
v8.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29109.json"