Incorrect authorization in ChurchCRM - CVE-2026-58408
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the CSVCreateFile.php endpoint when handling crafted export requests. A remote user can submit a specially crafted POST request directly to the export endpoint to disclose sensitive information.
The issue can expose the full personally identifiable information of every Person and Family record, including custom fields, by bypassing the intended export user interface.