CRITICAL🇵🇱 Wersja polska

CVE-2026-39339

CVSS 9.1v3.1pub. 2026-04-07upd. 2026-04-10

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the request URL, leading to complete exposure of church member data and system information. This vulnerability is fixed in 7.1.0.

🤖 AI Analysis
How it works

The middleware responsible for authenticating API requests checks for the presence of the string 'api/public' in the request URL. An attacker can place this string anywhere in the URL — even in a request directed to protected endpoints — which causes the middleware to incorrectly treat the request as public and skip user identity verification. The vulnerability requires no privileges, user interaction, or special network conditions (network vector, low attack complexity).

Impact

An attacker gains unauthorized access to all protected API endpoints, leading to complete disclosure of personal and contact information of church members as well as system configuration information. Unauthorized data modification is also possible (high impact on integrity).

Mitigation & patch

ChurchCRM should be updated to version 7.1.0 or later, in which the vulnerability has been fixed. Details are available in the vendor's references (GitHub Security Advisory GHSA-v3p2-mx78-pxhc).

Who is affected

ChurchCRM in all versions prior to 7.1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Churchcrm

    APP
    Churchcrm
    < 7.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-39342CRITICAL9.4PL ✓same product

SQL Injection w ChurchCRM przez parametr searchwhat (QueryView.php)

CVE-2026-39337CRITICAL10.0PL ✓same product

ChurchCRM: pre-auth RCE przez wstrzyknięcie kodu PHP w kreatorze instalacji

CVE-2026-35573CRITICAL9.1PL ✓same product

ChurchCRM: Path Traversal i RCE przez funkcję przywracania kopii zapasowej

CVE-2025-68110CRITICAL9.9PL ✓same product

ChurchCRM: ujawnienie danych logowania do bazy danych w komunikacie błędu

CVE-2025-67876CRITICAL9.3PL ✓same product

Stored XSS w ChurchCRM — przejęcie konta przez nazwy ról grup