# CVE-2026-29103

## Summary

- **CVE ID:** CVE-2026-29103
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-94, CWE-358
- **Published:** Mar 19, 2026
- **Last Modified:** Mar 20, 2026

## Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a direct Patch Bypass of CVE-2024-49774. Although the vendor attempted to fix the issue in version 7.14.5, the underlying flaw in ModuleScanner.php regarding PHP token parsing remains. The scanner incorrectly resets its internal state ($checkFunction flag) when encountering any single-character token (such as =, ., or ;). This allows attackers to hide dangerous function calls (e.g., system(), exec()) using variable assignments or string concatenation, completely evading the MLP security controls. Versions 7.15.1 and 8.9.3 patch the issue.

## Affected Products

- SuiteCRM — SuiteCRM (< 7.15.1)
- SuiteCRM — SuiteCRM (>= 8.0.0, < 8.9.3)

## References

- [CNA](https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5jjq-9qch-9rg7)
- [CNA](https://docs.suitecrm.com/admin/releases/7.15.x)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.50%
- **EPSS Percentile:** 41.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._