Code Injection in ChurchCRM - CVE-2026-39337

 

Code Injection in ChurchCRM - CVE-2026-39337

Published: May 5, 2026


Vulnerability identifier: #VU129690
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39337
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the install wizard configuration handling when processing setup data during the initial installation process. A remote attacker can inject arbitrary PHP code through the DB_PASSWORD parameter to execute arbitrary code.

Exploitation is possible before authentication during the initial setup workflow and can lead to complete server compromise.


Affected software

ChurchCRM

How to mitigate CVE-2026-39337

Install security update from vendor's website.

ChurchCRM - update to 7.1.0

External References

Related Security Bulletins