CVE-2026-39355Disclosure(kreaweb / genealogy)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch kreaweb genealogy systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted access to all genealogy data associated with the compromised team. This vulnerability is fixed in 5.9.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • genealogy

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
genealogy

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-07: 3PoC Mentioned / Linked · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 304-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-39355 Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user … https://www.cve.org/CVERecord?id=CVE-2026-39355

    Post summary

    The post announces CVE-2026-39355, noting a critical broken access control flaw in Genealogy before version 5.9.1, but offers no proof‑of‑concept, exploit, remediation, or active exploitation details.

    0000058
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39355: CRITICAL] Critical broken access control vulnerability in Genealogy PHP app (pre-5.9.1) allowed users to take over team workspaces. Update to 5.9.1 to mitigate this cyber security risk.#cve,CVE-2026-39355,#cybersecurity https://cvefind.com/CVE-2026-39355

    Post summary

    The post announces a critical broken access control flaw in Genealogy PHP app (pre-5.9.1) and recommends updating to 5.9.1 to mitigate the risk.

    0000038
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39355: Genealogy is Missing Authorizati... Missing auth check in `TeamController::transferOwnership()` = instant team hijacking with a single POST request - famil... https://zerodaysignal.com/vulnerability/CVE-2026-39355 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-39355, a missing authorization check in TeamController::transferOwnership() that allows instant team hijacking via a single POST request, and links to a zeroday signal page for further details.

    0000045
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkreawebgenealogy---

Explore more