Sceawere
Vulnerability Detail
CVE-2026-108713UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SuiteCRM Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- SuiteCRM
- Product
- SuiteCRM
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
SuiteCRM through 7.15.2 and 8.x through 8.10.2 contains a missing authorization vulnerability that allows authenticated users to create and modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Low-privileged users denied Campaigns access can post marketingId, campaignId, and templateId to reattach marketing messages or swap the template EmailMan sends in campaign emails.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:14.293Z",
"pubdate": "2026-10-11T13:17:14.293Z",
"executiveSummary": "A missing authorization vulnerability exists within SuiteCRM versions through 7.15.2 and 8.x through 8.10.2, residing in the setCampaignMarketingAndTemplate entry point.\nThis security flaw permits authenticated users with low privileges—specifically those explicitly denied access to the Campaigns module—to perform unauthorized operations on EmailMarketing records.\nBy manipulating the request parameters, attackers can reattach marketing messages or swap templates utilized by the EmailMan service for outgoing campaign communications.\nThe vulnerability represents a significant security risk, as it allows for the manipulation of marketing campaign content and structure, potentially leading to unauthorized communication dissemination or service disruption.\nExploitation requires the attacker to hold an authenticated session, but does not require administrative or high-level campaign management privileges, making this an elevation of privilege via improper access control.\nSuccessful exploitation allows attackers to bypass intended functional restrictions and modify sensitive email marketing configurations, undermining the integrity of the organization’s email outreach efforts.",
"technicalDetails": "The root cause of this vulnerability is a missing authorization check within the setCampaignMarketingAndTemplate entry point, which fails to validate whether the authenticated user possesses the appropriate permissions to modify or associate EmailMarketing records.\nIn SuiteCRM’s architecture, the entry point serves as an interface for processing campaign-related data. When a request is submitted to setCampaignMarketingAndTemplate, the application fails to verify the user's authorization level against the specific Campaign module access control lists (ACLs).\nAn attacker can exploit this by crafting HTTP POST requests containing specific parameters, including 'marketingId', 'campaignId', and 'templateId'. Because the backend logic lacks sufficient server-side validation or permission checks, the application processes these inputs and executes the association or update in the database without ensuring the user is authorized to perform such actions.\nThe attack flow follows these steps: First, the attacker identifies a legitimate user session. Second, the attacker triggers a POST request to the vulnerable entry point. Third, the attacker supplies arbitrary values for the campaign and template IDs. Finally, the server updates the database entries for the EmailMarketing module based on these parameters.\nBy swapping the 'templateId', an attacker can manipulate the content of outgoing emails triggered by the EmailMan scheduler. This allows for the redirection of campaign traffic or the distribution of altered content under the guise of an authorized campaign.\nThis vulnerability specifically affects the EmailMarketing component and is present in SuiteCRM 7.15.2 and below, as well as 8.10.2 and below. Authentication is required to reach the entry point, but no additional functional privileges (such as campaign administration) are validated by the vulnerable function.\nPost-exploitation impact includes the ability to interfere with email marketing delivery, alter campaign brand messaging, or potentially execute unauthorized mass communication using the platform's established SMTP infrastructure. This constitutes an improper access control vulnerability that enables unauthorized data modification within the CRM's marketing automation framework."
}