PT-2026-33527 · Churchcrm · Churchcrm
Published
2026-04-17
·
Updated
2026-04-18
·
CVE-2026-40582
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 7.2.0
Description
The '/api/public/user/login' endpoint validates only the username and password before returning the user's API key. This process bypasses the standard authentication flow, which includes account lockout and two-factor authentication (2FA) checks. An attacker who knows a user's password can obtain API access and reach all protected API endpoints with that user's privileges, even if the account is locked or 2FA is enabled.
Recommendations
Update to version 7.2.0.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm