Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-authentication-vulnerabilityopen-source-dependency-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisory

High-Severity Access Control and Session Forgery Flaws Patched in SuiteCRM and Auth0 PHP SDK

Updated 3mo agoFirst seen Mar 20, 20262 sources

SuiteCRM disclosed CVE-2026-29189, a high-severity insecure direct object reference (IDOR) flaw in its REST API V8 caused by missing ACL checks on user preferences and relationship endpoints. In versions before 7.15.1 and 8.9.3, authenticated users could access or modify data beyond their assigned permissions, creating high confidentiality and integrity risk in deployments of the open-source CRM platform. The issue is tracked as CWE-639 and carries a CVSS v3.1 rating reflecting low attack complexity and no user interaction requirement.

Auth0 also patched CVE-2026-34236 in the Auth0-PHP SDK, where insufficient entropy in cookie encryption allowed attackers to potentially brute-force encryption keys and forge session cookies. The flaw affects versions 8.0.0 through before 8.19.0 and is classified as CWE-331, with significant confidentiality and integrity impact for applications relying on the SDK for authentication. Auth0 fixed the issue in 8.19.0, while SuiteCRM remediated its API authorization weakness in 7.15.1 and 8.9.3.

Share:
High-Severity Access Control and Session Forgery Flaws Patched in SuiteCRM and Auth0 PHP SDK
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 1, 20263mo ago

CVE-2026-34236 for Auth0-PHP SDK is received and disclosed

The CVE entry for the Auth0-PHP SDK cookie encryption weakness was received by security-advisories@github.com and publicly disclosed. The flaw was assigned CWE-331 and carried significant confidentiality and integrity risk.

Auth0 patches insufficient entropy flaw in auth0-PHP SDK 8.19.0

Auth0 fixed a vulnerability in the auth0-PHP SDK where insufficient entropy in cookie encryption could allow brute-forcing of the encryption key and forged session cookies. The issue affected versions 8.0.0 through before 8.19.0 and was patched in version 8.19.0.

Mar 20, 20263mo ago

CVE-2026-29189 for SuiteCRM is received and disclosed

The CVE entry for SuiteCRM's REST API V8 IDOR vulnerability was received by security-advisories@github.com. The flaw was classified as CWE-639 and described as having high confidentiality and integrity impact.

SuiteCRM fixes REST API V8 IDOR in versions 7.15.1 and 8.9.3

SuiteCRM addressed a missing access control vulnerability in its REST API V8 that allowed authenticated users to access or manipulate data beyond their permissions via user preferences and relationship endpoints. The issue affected versions before 7.15.1 and 8.9.3.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
2 linked
Auth0GitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.