CVE-2026-29098 | SuiteCRM up to 7.15.0/8.9.2 ModuleBuilder controller.php action_exportCustom modules/name path traversal (GHSA-6858-fhw5-56gf)
A vulnerability classified as problematic has been found in SuiteCRM up to 7.15.0/8.9.2. This affects the function action_exportCustom of the file modules/ModuleBuilder/controller.php of the component ModuleBuilder Module. Performing a manipulation of the argument modules/name results in relative path traversal.
This vulnerability was named CVE-2026-29098. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.