CVE-2025-54786
SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data
5.3
MEDIUM
CVSS 3.1
EPSS 0.18%
Description
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.
How to fix CVE-2025-54786
To remediate CVE-2025-54786, upgrade the affected package to a fixed version below.
- —upgrade to 7.14.7 or later
Is CVE-2025-54786 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.14.6, < 7.14.7, >= 8.8.0, < 8.8.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |