Detects SuiteCRM instances before version 7.15.1 (or 8.9.3 for 8.x) where the getUserNameFilter() function in LDAPAuthenticateUser.php embeds usernames directly into LDAP search filters without ldap_escape(). On LDAP-configured instances, attackers can inject filter operators to bypass authentication or enumerate users.
Is your app exploitable through CVE-2026-33289?
Scan your domain free