Authorization bypass through user-controlled key in ChurchCRM - #VU138414

 

Authorization bypass through user-controlled key in ChurchCRM - #VU138414

Published: July 20, 2026


Vulnerability identifier: #VU138414
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access and modify records outside the authorized event roster.

The vulnerability exists due to improper access control in the kiosk device check-in, check-out, and notification endpoints when processing a client-supplied PersonId. A remote user can submit a crafted request with an arbitrary PersonId to access and modify records outside the authorized event roster.

The issue affects admin-accepted kiosk devices assigned to an event, and can impact attendance records, timeline notes, and family notifications for people not on the kiosk's active class roster.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.4.3

External References

Related Security Bulletins