CVE-2026-29097
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1 and 8.9.3 contain a Server-Side Request Forgery (SSRF) vulnerability combined with a Denial of Service (DoS) condition in the RSS Feed Dashlet component. Versions 7.15.1 and 8.9.3 patch the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://docs.suitecrm.com/admin/releases/7.15.x, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29097.json, https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-x3p2-qcqh-qx2m, https://nvd.nist.gov/vuln/detail/CVE-2026-29097
