Cyber Posture

CVE-2026-29101

Medium

Published: 19 March 2026

Published
19 March 2026
Modified
24 March 2026
KEV Added
Patch
CVSS Score 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0002 6.6th percentile
Risk Priority 10 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-29101 is a medium-severity Relative Path Traversal (CWE-23) vulnerability in Suitecrm Suitecrm. Its CVSS base score is 4.9 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 6.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SC-5 (Denial-of-service Protection) and SI-10 (Information Input Validation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Application or System Exploitation (T1499.004). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Timely flaw remediation through applying SuiteCRM patches in versions 7.15.1 and 8.9.3 directly eliminates this specific DoS vulnerability in modules.

prevent

Denial-of-service protection directly limits the effects of this high-privilege network-accessible DoS attack on SuiteCRM availability.

prevent

Information input validation prevents relative path traversal (CWE-23) exploits that enable this DoS condition in SuiteCRM modules.

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

The CVE describes a network-reachable application vulnerability (path traversal leading to resource exhaustion) that a high-privileged attacker can directly exploit to crash or deny service to the SuiteCRM instance, mapping exactly to T1499.004 Application or System Exploitation.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

Deeper analysisAI

CVE-2026-29101 is a Denial-of-Service (DoS) vulnerability (CWE-23) affecting SuiteCRM, an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The issue resides in SuiteCRM modules and impacts versions prior to 7.15.1 and 8.9.3. It has a CVSS v3.1 base score of 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H), indicating medium severity primarily due to high availability impact with no confidentiality or integrity effects.

An attacker with high privileges can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation results in a DoS condition, disrupting service availability for the affected SuiteCRM instance without compromising data confidentiality or integrity.

SuiteCRM versions 7.15.1 and 8.9.3 address the vulnerability with patches. Additional details are available in the SuiteCRM 7.15.x release documentation at https://docs.suitecrm.com/admin/releases/7.15.x and the GitHub security advisory at https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-24pf-9cvh-ppcg.

Details

CWE(s)

Affected Products

suitecrm
suitecrm
≤ 7.15.1 · 8.0.0 — 8.9.3

CVEs Like This One

CVE-2026-29097Same product: Suitecrm Suitecrm
CVE-2026-29102Same product: Suitecrm Suitecrm
CVE-2026-29103Same product: Suitecrm Suitecrm
CVE-2026-29096Same product: Suitecrm Suitecrm
CVE-2026-33288Same product: Suitecrm Suitecrm
CVE-2026-29100Same product: Suitecrm Suitecrm
CVE-2026-29189Same product: Suitecrm Suitecrm
CVE-2026-29109Same product: Suitecrm Suitecrm
CVE-2026-33289Same product: Suitecrm Suitecrm
CVE-2026-29099Same product: Suitecrm Suitecrm

References