Improper Restriction of Excessive Authentication Attempts in ChurchCRM - #VU142437

 

Improper Restriction of Excessive Authentication Attempts in ChurchCRM - #VU142437

Published: August 13, 2026


Vulnerability identifier: #VU142437
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass two-factor authentication.

The vulnerability exists due to improper restriction of excessive authentication attempts in the TOTP verification logic in the API and browser login flows when processing repeated OTP verification requests after a correct password has been supplied. A remote attacker can submit repeated guessed TOTP or recovery codes to bypass two-factor authentication.

Exploitation requires knowledge of the victim\'s password and that the victim has two-factor authentication enabled. Recovery codes are affected through the same verification branch.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.6.0

External References

Related Security Bulletins