CVE-2025-54786: Salesagility Suitecrm

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.

Affected products

  • Salesagility Suitecrm: version 7.14.6 only; version 8.8.0 only

Published 2025-08-07. Last modified 2026-06-17.