CVE-2026-29099 | SuiteCRM up to 7.15.0/8.9.2 OutboundEmail.php retrieve ID sql injection (GHSA-38rf-h37x-7767)
A vulnerability labeled as critical has been found in SuiteCRM up to 7.15.0/8.9.2. Affected is the function retrieve of the file include/OutboundEmail/OutboundEmail.php. The manipulation of the argument ID results in sql injection.
This vulnerability is known as CVE-2026-29099. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.