
CVE-2026-39331 ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by s… https://www.cve.org/CVERecord?id=CVE-2026-39331
Post summary
The post announces CVE‑2026‑39331, noting that an authenticated API user can arbitrarily modify family records in ChurchCRM, but provides no PoC, exploit code, or patch details.
