Authorization bypass through user-controlled key in ChurchCRM - #VU138414
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote user to access and modify records outside the authorized event roster.
The vulnerability exists due to improper access control in the kiosk device check-in, check-out, and notification endpoints when processing a client-supplied PersonId. A remote user can submit a crafted request with an arbitrary PersonId to access and modify records outside the authorized event roster.
The issue affects admin-accepted kiosk devices assigned to an event, and can impact attendance records, timeline notes, and family notifications for people not on the kiosk's active class roster.