Authorization bypass through user-controlled key in ChurchCRM - CVE-2026-58410

 

Authorization bypass through user-controlled key in ChurchCRM - CVE-2026-58410

Published: July 20, 2026


Vulnerability identifier: #VU138410
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58410
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify records.

The vulnerability exists due to authorization bypass through a user-controlled key in the family API endpoints when handling requests with an attacker-controlled familyId. A remote user can supply another family's familyId to read profile data, notes, and timeline entries, and create notes on another family's record to disclose sensitive information and modify records.

Note read and write access requires the Notes permission.


Affected software

ChurchCRM

How to mitigate CVE-2026-58410

Install security update from vendor's website.

ChurchCRM - update to 7.4.0

External References

Related Security Bulletins