
🚨 CVE-2026-39337: ChurchCRM Affected by Unauthenti... Unsanitized $dbPassword in setup wizard = instant shell access during fresh installs - incomplete CVE-2025-62521 patch ... https://zerodaysignal.com/vulnerability/CVE-2026-39337 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE‑2026‑39337 in ChurchCRM, noting that an unsanitized $dbPassword in the setup wizard allows instant shell access during fresh installs, with no mention of patches, exploits, or active use.
