CVE-2026-58410
ChurchCRM CRM
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated non-admin user with EditSelf access can supply another family’s `familyId` and access records outside their own family scope. The backend trusts the attacker-controlled `familyId` and loads the corresponding family entity by ID without verifying that the requested family belongs to the current user. If the same user also has Notes permission, they can create...
- CVSS
- 7.1
- EPSS
- 0.17% 7.17% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14