๐Ÿ” CVE Alert

CVE-2026-29109

UNKNOWN 0.0

SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Processing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
13th

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator to execute arbitrary system commands on the server. `FilterDefinitionProvider.php` calls `unserialize()` on user-controlled data from the `saved_search.contents` database column without restricting instantiable classes. Version 8.9.3 patches the issue.

CWE CWE-502
Vendor suitecrm
Product suitecrm-core
Published Mar 19, 2026
Last Updated Mar 20, 2026
Stay Ahead of the Next One

Get instant alerts for suitecrm suitecrm-core

Be the first to know when new unknown vulnerabilities affecting suitecrm suitecrm-core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SuiteCRM / SuiteCRM-Core
< 8.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SuiteCRM/SuiteCRM-Core/security/advisories/GHSA-mhq2-277m-6w24