Authorization bypass through user-controlled key in ChurchCRM - CVE-2026-58410
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify records.
The vulnerability exists due to authorization bypass through a user-controlled key in the family API endpoints when handling requests with an attacker-controlled familyId. A remote user can supply another family's familyId to read profile data, notes, and timeline entries, and create notes on another family's record to disclose sensitive information and modify records.
Note read and write access requires the Notes permission.