CVE-2026-39339Disclosure(churchcrm / churchcrm)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch churchcrm churchcrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the request URL, leading to complete exposure of church member data and system information. This vulnerability is fixed in 7.1.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-07); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-07: 3Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-04: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 3Technical Details · 2026-05-04: 104-0705-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure2Patch1
2026-05-041
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-39339 - critical 🚨 ChurchCRM - API Authentication Bypass via URL Injection > ChurchCRM < 7.1.0 contains an authentication bypass caused by improper API middleware... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-39339 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-39339—a critical authentication bypass in ChurchCRM version 7.1.0 and below. It cites a PoC link but does not discuss patches, exploit tools, or active exploitation.

    00031205
    973 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39339: ChurchCRM has an API Authenticat... String matching fail in AuthMiddleware lets anyone bypass API auth with "api/public" in URL - classic case of substring... https://zerodaysignal.com/vulnerability/CVE-2026-39339 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-39339, a string‑matching flaw in ChurchCRM’s AuthMiddleware that permits API authentication bypass, and links to a vulnerability page without indicating exploitation or patch status.

    0000048
    204 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39339 ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Mi… https://www.cve.org/CVERecord?id=CVE-2026-39339

    Post summary

    The post announces a critical authentication bypass flaw (CVE-2026-39339) in ChurchCRM's API middleware before version 7.1.0, providing vulnerability details but no PoC, exploit, patch, or active exploitation evidence.

    0000088
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39339: CRITICAL] Critical security flaw in ChurchCRM fixed! An authentication bypass vulnerability in its API middleware allowed unauthorized access to sensitive data. Update to version 7.1.0 now.#cve,CVE-2026-39339,#cybersecurity https://cvefind.com/CVE-2026-39339

    Post summary

    ChurchCRM has released a patch (v7.1.0) that fixes a critical authentication bypass flaw in its API middleware, preventing unauthorized data access.

    00000299
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more