Released 31st July 2026
This release removes SOAP Portal support. If you are using SOAP Portal, please migrate to REST API or other supported methods.
A new configuration option disable_v4_api_query_where has been added. This option allows administrators to disable the v4 API query where clause. By default, this option is set to true, meaning the v4 API query where clause is disabled. To enable it, set the option to false in the config_override.php.
CVE: CVE-2026-61653: SQL Injection | GitHub Advisory | Reporter: Nguy Minh Tuan (@minhtuanact) of Sun* Cyber Security Research Team
CVE: CVE-2026-61649: SSRF Vulnerability | GitHub Advisory | Reporter: morimori-dev
CVE: CVE-2026-61650: Improper Access Control | GitHub Advisory | Reporter: larlarua
CVE: CVE-2026-61651: SQL Injection | GitHub Advisory | Reporter: Security Researcher Ahmed Mosaa
CVE: CVE-2026-61653: SQL Injection | GitHub Advisory | Reporter: Nguy Minh Tuan (@minhtuanact) of Sun* Cyber Security Research Team
CVE: CVE-Pending: SQL Injection | GitHub Advisory | Reporter: marginaldeer
CVE: CVE-2026-69134: SQL Injection | GitHub Advisory | Reporter: Tristan Madani (@TristanInSec) from Talence Security
CVE: CVE-2026-69135: SQL Injection | GitHub Advisory | Reporter: Security Researcher Ahmed Mosaa
CVE: CVE-2026-69136: SQL Injection | GitHub Advisory | Reporter: Security Researcher Ahmed Mosaa
CVE: CVE-2026-69137: SSRF Vulnerability | GitHub Advisory | Reporter: Max Gabriel (EntroVyx)
CVE: CVE-2026-69140: SQL Injection | GitHub Advisory | Reporter: Nguy Minh Tuan (@minhtuanact) of Sun* Cyber Security Research Team
CVE: CVE-2026-69141: SQL Injection | GitHub Advisory | Reporter: Nguy Minh Tuan (@minhtuanact) of Sun* Cyber Security Research Team
CVE: CVE-2026-69142: SQL Injection | GitHub Advisory | Reporter: AdrianJunge
CVE: CVE-2026-69143: SQL Injection | GitHub Advisory | Reporter: Security Researcher Ahmed Mosaa
CVE: CVE-2026-69144: Improper Access Control | GitHub Advisory | Reporter: Yash Shendge (GitHub: ashrexon)
CVE: CVE-2026-63111: Improper Access Control | GitHub Advisory | Reporter: Pedro J. Núñez-Cacho Fuentes (tunelko / blogs.tunelko.com)
CVE: CVE-2026-63213: Path Traversal | GitHub Advisory | Reporter: Khương Anh (@leduckhuong)
CVE: CVE-2026-63214: SQL Injection | GitHub Advisory | Reporter: radoi-teodor
CVE: CVE-2026-63215: SQL Injection | GitHub Advisory | Reporter: Furkan KARAARSLAN https://www.linkedin.com/in/furkan-k/
CVE: CVE-2026-63217: IDOR Vulnerability | GitHub Advisory | Reporter: geo-chen
CVE: CVE-2026-63218: Improper Access Control | GitHub Advisory | Reporter: Yash Shendge (GitHub: ashrexon)
CVE: CVE-Pending: SQL Injection | GitHub Advisory | Reporter: Anonymous
CVE: CVE-2026-71550: LFI to RCE Vulnerability | GitHub Advisory | Reporter: amwhoi
CVE: CVE-2026-71548: SQL Injection | GitHub Advisory | Reporter: Ahmed Alshammari (isch1zo)
CVE: CVE-Pending: SQL Injection | GitHub Advisory | Reporter: AdrianJunge
CVE: CVE-Pending: RCE Vulnerability | GitHub Advisory | Reporter: MichaelPasternak1337
CVE: CVE-Pending: SQL Injection | GitHub Advisory | Reporter: Security Researcher Ahmed Mosaa
CVE: CVE-Pending: Improper Access Control | GitHub Advisory | Reporter: voraci0us
CVE: CVE-Pending: Improper Access Control | GitHub Advisory | Reporter: usmonkhudoyorov
CVE: CVE-Pending: Improper Access Control | GitHub Advisory | Reporter: adilkhan7546
CVE: CVE-Pending: Improper Access Control | GitHub Advisory | Reporter: MichaelPasternak1337
CVE: CVE-Pending: Improper Access Control | GitHub Advisory | Reporter: TA-MU-TA
PR #9773 - Fix #9772: Importing text emails with attachments
PR #10807 - Fix #10804: CalendarSync sync-back preserves external fields
PR #10478 - Fix #10477: Do not exclude email sends from the message queue without filtering by campaign
PR #10822 - Fix #8289: Fix Import data for floating point fields wrongly saved
PR #10501 - Fix #10499: Error when importing in the Locations module
PR #10849 - Update composer dependencies
PR #10831 - Fix #10830: Primary email doesn’t update when importing
PR #10838 - Fix #10594: Bad relationship definitions filling the suitecrm logs
PR #10826 - Fix #10825: Truncated value when saving large values in workflow and report conditions
PR #10875 - Fix #10874: 'Associated user' field in OAuth Clients and Tokens lists does not link correctly
PR #10869 - Fix #10763: SMTP credentials wrong after changing a field in outbound email settings
PR #10860 - Fix #10859: Auth window loses connection to the opener when requesting an OAuth token
Fix #3855 - Update PDF Template Samples
Fix #7687 - update sample pdf loader to ignore invalid files
Fix issue in Email automatic import scheduler where Emails from certain timezones were not importing correctly.
Mostly affected Emails where the difference in timezone made the original Email fall on a different day
SuiteCRM is built with and for its community — thank you to everyone who reported issues, submitted feedback, and contributed code to this release.
Special thanks to the following contributors for their contributions to this release:
Special thanks to everyone who reported the security issues addressed in this release!
Nagarajan Selvaraj Paulmony
Visit Releases for the appropriate upgrade package for your installation.
Found a Bug? Submit an Issue
Want to contribute? Open a Pull Request
Translations: Join us on Crowdin
To report a security issue, please follow our Security Policy.
Released 19th March 2026
CVE: CVE-2026-29189: Improper Access Control | GitHub Advisory | Reporter: lighthousekeeper1212
CVE: CVE-2026-29100: HTML Injection Vulnerability | GitHub Advisory | Reporter: Dimitris Mitropoulos, University of Athens and National Infrastructures for Research and Technology - GRNET
CVE: CVE-2026-29098: Path Traversal Vulnerability | GitHub Advisory | Reporter: JBince
CVE: CVE-2026-29099: SQL Injection Vulnerability | GitHub Advisory | Reporter: JBince
CVE: CVE-2026-29102: RCE Vulnerability | GitHub Advisory | Reporter: Reuben Seah
CVE: CVE-2026-29101: Path Traversal Vulnerability | GitHub Advisory | Reporter: Reuben Seah
CVE: CVE-2026-29105: Open Redirect Vulnerability | GitHub Advisory | Reporter: d3dn0v4
CVE: CVE-2026-29104: Authenticated Arbitrary File Upload Vulnerability | GitHub Advisory | Reporter: d3dn0v4
CVE: CVE-2026-29106: XSS Vulnerability | GitHub Advisory | Reporter: Suphawith Phusanbai
CVE: CVE-2026-29107: Authenticated SSRF Vulnerability | GitHub Advisory | Reporter: Parnuski
CVE: CVE-2026-29097: SSRF and Dos Vulnerability | GitHub Advisory | Reporter: Ravindu Wickramasinghe (rvz)
CVE: CVE-2026-29103: RCE Vulnerability | GitHub Advisory | Reporter: DQH1
CVE: CVE-2026-29096: SQL Injection Vulnerability | GitHub Advisory | Reporter: q1uf3ng
CVE: CVE-2026-33288: SQL Vulnerability | GitHub Advisory | Reporter: Guilherme Mury (Kilserv)
CVE: CVE-2026-33288: LDAP Injection Vulnerability | GitHub Advisory | Reporter: Guilherme Mury (Kilserv)
PR: 10753 - Added Redis Password and configuration documentation to SugarCacheRedis.php
PR: 9388 - Optimise Export Memory Usage
PR: 7317 - Fix #7316 - Delete Vardefs files after deleting custom field
PR: 10751 - SugarApplication::redirect adds "Location", calling with "Location" doubles it result is not working
PR: 10781 - Fix #10780 issue with language file being overwritten
PR: 10631 - Fix #10630 - Scheduled task “Run Email Reminder Notifications” does not run when deleting a person
PR: 10707 - Fix #10621 - Localize checkbox values in PDF templates
PR: 10768 - Fix #10767 Image field comes with an extra "10" in image src
PR: 10677 - Fix #10676 - Remove old query which duplicates email address in table
PR: 10779 - Update Dependencies
PR: 10514 - Fix #10513 - When field to be updated is email1 then use new logic to update related email account record
PR: 10761 - Fix #10759 Fix issue with white screen on login after requesting 2nd 2FA code
PR: 10760 - Fix #9450 - Prevent Spaces in Grouped Report Ids
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
Released 18 December 2025
Lucene Global Search is now officially deprecated.
If you currently use Lucene, it will remain functional after the upgrade to 7.15.0. However, we strongly recommend transitioning to an alternative search mechanism, as support will be removed in a future release.
Support for PHP 8.4: SuiteCRM is now fully compatible with PHP 8.4.
In PHP 8.4, the IMAP extension is no longer bundled. Ensure your environment is configured correctly. See PHP 8.4 Change Log.
Minimum Version Bump: To ensure security and performance, the minimum supported version is now PHP 8.1.
We have introduced more granular controls for automatic email importing to reduce server load and improve accuracy:
Unread Only: Fetch only unread emails during import.
Custom Start Points: Set a specific starting date/point for new mailbox imports.
Threshold Limits: Define the maximum number of emails imported per scheduled run.
Global defaults can be managed in Admin > Email Settings, or overridden for individual inbound accounts.
To see more information on these new configuration options, please refer to the Automatic Email Importing documentation.
The calendar experience has been overhauled with a focus on interoperability:
Calendar Invite Support: SuiteCRM meeting and call invites now support "Calendar Invite" functionality for both Google Calendar, Outlook and many more.
When a user receives a SuiteCRM meeting or call invite, they will be able to add the event directly to their calendar with a single click.
Admin Sync Settings: A new dedicated section in the Administration panel for global synchronization behavior.
New "Calendar Accounts" Module: Manage all connections (including new CalDAV support) directly from your User Profile.

To learn more about setting up Calendar integration and the configuration options available, please refer to the Calendar Configuration documentation.
TinyMCE 8: The text editor has been upgraded to provide a consistent look and feel across all SuiteCRM modules.
Responsive Surveys: Improved CSS styling ensures that Surveys look professional and remain easy to use on mobile devices and tablets.
V8 API: OAuth Auth Code Grant: We now support the Authorization Code Grant flow, allowing for more secure, industry-standard authentication for external applications.

To learn more information on what an Auth Code Grant is and how to set it up, please refer to the OAuth Authorization Code Grant Type documentation.
New or updated guides are available for:
Special thanks to the following members for their contributions and participation in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy
Content is available under GNU Free Documentation License 1.3 or later unless otherwise noted.