Description
SuiteCRM through 7.15.2 and 8.10.2 contains a missing authorization vulnerability in the DetailUserRole entry point that allows authenticated non-admin users to view other users' ACL data. Attackers can supply another non-admin user's id in the record parameter to read that user's assigned roles and per-module ACL action matrix.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to ACL and role data
Action: Apply Patch
AI Analysis

Impact

SuiteCRM versions 7.15.2 and 8.10.2 contain a missing authorization flaw in the DetailUserRole entry point that allows any authenticated non‑admin user to query another user’s record identifier in order to read that user’s assigned roles and per‑module access control list matrix. This flaw is a classic CWE‑862 Missing Authorization vulnerability that can leak confidential ACL configuration and potentially support privilege escalation attempts by revealing role assignments and permissions to a non‑privileged user.

Affected Systems

The vulnerability affects all installations of SuiteCRM 7.15.2 and SuiteCRM 8.10.2 only. Any deployment of these specific versions that exposes the DetailUserRole entry point is susceptible; newer releases have addressed the issue and older or other major branches are not impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, suggesting limited publicly known exploitation. The flaw is exploitable by any authenticated user who has network access to the application, making it a remote authenticated attack vector. Because the impact is limited to disclosure of ACL data and does not directly grant privilege escalation, the overall risk remains moderate, but it is important to remediate to prevent potential future exploitation of exposed role information.

Generated by OpenCVE AI on October 11, 2026 at 13:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SuiteCRM to the latest available release that contains the fix for DetailUserRole.
  • Restrict or disable the DetailUserRole entry point so that only users with administrative privileges can access it.
  • Review and tighten ACL configurations to ensure that non‑admin users cannot request or view other users’ role data.

Generated by OpenCVE AI on October 11, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description SuiteCRM through 7.15.2 and 8.10.2 contains a missing authorization vulnerability in the DetailUserRole entry point that allows authenticated non-admin users to view other users' ACL data. Attackers can supply another non-admin user's id in the record parameter to read that user's assigned roles and per-module ACL action matrix.
Title SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via DetailUserRole Entry Point
First Time appeared Suitecrm
Suitecrm suitecrm
Weaknesses CWE-862
CPEs cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*
Vendors & Products Suitecrm
Suitecrm suitecrm
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Suitecrm Suitecrm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:26.085Z

Reserved: 2026-10-11T01:51:37.551Z

Link: CVE-2026-108712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:14.047

Modified: 2026-10-11T13:17:14.047

Link: CVE-2026-108712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses