Description
SuiteCRM through 7.15.2 and 8.x through 8.10.2 contains a missing authorization vulnerability that allows authenticated users to create and modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Low-privileged users denied Campaigns access can post marketingId, campaignId, and templateId to reattach marketing messages or swap the template EmailMan sends in campaign emails.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

SuiteCRM versions 7.15.2 and 8.x through 8.10.2 expose a missing authorization flaw that lets an authenticated user create or modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Users who do not normally have Campaigns access can post marketingId, campaignId, and templateId, which reattaches marketing messages or swaps the email template sent to campaign recipients. This flaw compromises the integrity of campaign content and allows malicious users to deliver altered or deceptive marketing emails.

Affected Systems

The vulnerability affects the SuiteCRM application. All installations running SuiteCRM 7.15.2 and those in the 8.x series up to and including 8.10.2 are impacted.

Risk and Exploitability

The CVSS score of 5.3 suggests a medium severity. Because the flaw is exploitable only by authenticated users and requires no special environmental conditions, the risk is manageable but non‑negligible. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. An attacker who possesses a user account—especially one with limited Campaigns permissions—can post to setCampaignMarketingAndTemplate and alter marketing templates, potentially compromising the integrity of campaign communications.

Generated by OpenCVE AI on October 11, 2026 at 13:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest SuiteCRM patch or upgrade to a version newer than 8.10.2 that addresses the missing authorization in setCampaignMarketingAndTemplate.
  • Re‑evaluate ACLs and remove Campaigns access from low‑privileged users, ensuring they cannot invoke the vulnerable entry point.
  • If the setCampaignMarketingAndTemplate entry point is not required, configure it for restricted access or disable it entirely to block unauthorized POST requests.

Generated by OpenCVE AI on October 11, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description SuiteCRM through 7.15.2 and 8.x through 8.10.2 contains a missing authorization vulnerability that allows authenticated users to create and modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Low-privileged users denied Campaigns access can post marketingId, campaignId, and templateId to reattach marketing messages or swap the template EmailMan sends in campaign emails.
Title SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via setCampaignMarketingAndTemplate
First Time appeared Suitecrm
Suitecrm suitecrm
Weaknesses CWE-862
CPEs cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*
Vendors & Products Suitecrm
Suitecrm suitecrm
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Suitecrm Suitecrm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:26.741Z

Reserved: 2026-10-11T01:51:48.065Z

Link: CVE-2026-108713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:14.293

Modified: 2026-10-11T13:17:14.293

Link: CVE-2026-108713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses