Incorrect authorization in ChurchCRM - CVE-2026-58408

 

Incorrect authorization in ChurchCRM - CVE-2026-58408

Published: July 20, 2026


Vulnerability identifier: #VU138412
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58408
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the CSVCreateFile.php endpoint when handling crafted export requests. A remote user can submit a specially crafted POST request directly to the export endpoint to disclose sensitive information.

The issue can expose the full personally identifiable information of every Person and Family record, including custom fields, by bypassing the intended export user interface.


Affected software

ChurchCRM

How to mitigate CVE-2026-58408

Install security update from vendor's website.

ChurchCRM - update to 7.4.0

External References

Related Security Bulletins