CVE-2026-35573Disclosure(churchcrm / churchcrm)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch churchcrm churchcrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-07: 3PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-04-07: 1Patch / Workaround · 2026-04-07: 2Technical Details · 2026-04-07: 304-07
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35573: CRITICAL] ChurchCRM, an open-source church management system, fixed a path traversal vulnerability in version 6.5.3, preventing remote code execution for authenticated admins during file upl...#cve,CVE-2026-35573,#cybersecurity https://cvefind.com/CVE-2026-35573

    Post summary

    ChurchCRM released a patch in version 6.5.3 that resolves a critical path traversal flaw, preventing authenticated admins from achieving remote code execution.

    0000035
    619 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-35573: ChurchCRM has a Path traversal l... Admin-to-RCE via directory traversal in backup restore - classic filename validation bypass lets you drop shells throug... https://zerodaysignal.com/vulnerability/CVE-2026-35573 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reveals a new ChurchCRM vulnerability (CVE-2026-35573) that permits directory traversal in backup restore, resulting in administrative remote code execution and the ability to drop shells.

    0000047
    204 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35573 ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated … https://www.cve.org/CVERecord?id=CVE-2026-35573

    Post summary

    The post announces a path‑traversal flaw in ChurchCRM’s backup restore before version 6.5.3, indicating that upgrading removes the vulnerability but provides no PoC, exploit, or active‑use evidence.

    0000091
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more