Sceawere
Vulnerability Detail
CVE-2026-108712UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthorized ACL Data Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- SuiteCRM
- Product
- SuiteCRM
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SuiteCRM through 7.15.2 and 8.10.2 contains a missing authorization vulnerability in the DetailUserRole entry point that allows authenticated non-admin users to view other users' ACL data. Attackers can supply another non-admin user's id in the record parameter to read that user's assigned roles and per-module ACL action matrix.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:14.047Z",
"pubdate": "2026-10-11T13:17:14.047Z",
"executiveSummary": "This vulnerability is classified as an authorization bypass, specifically an Insecure Direct Object Reference (IDOR) or missing authorization issue, within the SuiteCRM application.\nThe flaw allows authenticated non-administrative users to access sensitive Access Control List (ACL) data belonging to other users within the system.\nAffected versions include SuiteCRM through 7.15.2 and 8.10.2.\nThe risk implication is a breach of confidentiality regarding internal user roles and granular permission configurations.\nAn attacker requires valid authenticated access to the application as a non-privileged user to exploit this vulnerability.\nBy manipulating the 'record' parameter within the 'DetailUserRole' entry point, an attacker can enumerate and view the assigned roles and the module-specific ACL action matrix of any other user in the database.\nThis exposure provides attackers with deep insights into the security structure of the CRM, which could be leveraged for further privilege escalation or targeted attacks against specific users based on their elevated or unique permissions.",
"technicalDetails": "The vulnerability resides within the 'DetailUserRole' entry point of the SuiteCRM application, which fails to implement adequate server-side authorization checks when retrieving user-specific Access Control List (ACL) configurations.\nThe root cause is a failure to validate that the authenticated session user possesses the requisite administrative privileges to view the security profile of another account.\nIn the affected versions (SuiteCRM 7.15.2 and 8.10.2), the application relies on an insecure implementation of object-level authorization, allowing the 'record' parameter—which identifies the target user ID—to be manipulated by the requester.\nThe exploitation flow is as follows: 1) The attacker authenticates as a standard, non-privileged user. 2) The attacker intercepts the request to the 'DetailUserRole' entry point. 3) The attacker modifies the 'record' parameter in the HTTP GET request to correspond to the target user's UUID. 4) The server processes this request and returns the sensitive metadata associated with that record, including assigned security roles and the full per-module ACL action matrix (e.g., granular permissions for Create, Delete, Edit, Export, Import, List, and View).\nThis lack of authorization allows for the systematic enumeration of user security structures. Because the API returns the specific permission matrix, an attacker can map the CRM's internal security landscape, identifying which users hold administrative privileges or elevated access to specific modules.\nThe vulnerability does not require administrative access, only standard authentication, making it reachable by any user account created in the system. The payload behavior is strictly read-only, but the information leaked is high-value for reconnaissance in complex environments where role-based access control (RBAC) is heavily relied upon.\nThe issue exists entirely on the server-side, meaning there is no client-side obfuscation that can prevent this exposure. Once the request is directed at the 'DetailUserRole' endpoint with a valid session cookie, the backend logic erroneously trusts the provided input without verifying if the requesting user ID is authorized to access the requested object ID."
}