CVE-2026-29097 | SuiteCRM up to 7.15.0/8.9.2 RSS Feed Dashlet server-side request forgery (GHSA-x3p2-qcqh-qx2m)
A vulnerability described as critical has been identified in SuiteCRM up to 7.15.0/8.9.2. The affected element is an unknown function of the component RSS Feed Dashlet. Executing a manipulation can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-29097. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.