Incorrect authorization in ChurchCRM - #VU142444

 

Incorrect authorization in ChurchCRM - #VU142444

Published: August 13, 2026


Vulnerability identifier: #VU142444
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read and modify arbitrary person records.

The vulnerability exists due to improper access control in the person-properties API routes when handling requests for arbitrary personId values. A remote user can send crafted API requests to read and modify arbitrary person records.

The issue affects accounts with MenuOptions permission but without EditRecords permission, and enables reading, adding, updating, and removing custom property assignments on other users\' person records.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.6.0

External References

Related Security Bulletins