SuiteCRM disclosed CVE-2026-29189, a high-severity insecure direct object reference (IDOR) flaw in its REST API V8 caused by missing ACL checks on user preferences and relationship endpoints. In versions before 7.15.1 and 8.9.3, authenticated users could access or modify data beyond their assigned permissions, creating high confidentiality and integrity risk in deployments of the open-source CRM platform. The issue is tracked as CWE-639 and carries a CVSS v3.1 rating reflecting low attack complexity and no user interaction requirement.
Auth0 also patched CVE-2026-34236 in the Auth0-PHP SDK, where insufficient entropy in cookie encryption allowed attackers to potentially brute-force encryption keys and forge session cookies. The flaw affects versions 8.0.0 through before 8.19.0 and is classified as CWE-331, with significant confidentiality and integrity impact for applications relying on the SDK for authentication. Auth0 fixed the issue in 8.19.0, while SuiteCRM remediated its API authorization weakness in 7.15.1 and 8.9.3.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for the Auth0-PHP SDK cookie encryption weakness was received by security-advisories@github.com and publicly disclosed. The flaw was assigned CWE-331 and carried significant confidentiality and integrity risk.
Auth0 fixed a vulnerability in the auth0-PHP SDK where insufficient entropy in cookie encryption could allow brute-forcing of the encryption key and forged session cookies. The issue affected versions 8.0.0 through before 8.19.0 and was patched in version 8.19.0.
The CVE entry for SuiteCRM's REST API V8 IDOR vulnerability was received by security-advisories@github.com. The flaw was classified as CWE-639 and described as having high confidentiality and integrity impact.
SuiteCRM addressed a missing access control vulnerability in its REST API V8 that allowed authenticated users to access or manipulate data beyond their permissions via user preferences and relationship endpoints. The issue affected versions before 7.15.1 and 8.9.3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.