CVE-2026-40582Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authentication checks. An attacker with knowledge of a user's password can obtain API access even when the account is locked or has 2FA enabled, granting direct access to all protected API endpoints with that user's privileges. This issue has been fixed in version 7.2.0. Note: this issue had a duplicate, GHSA-472m-p3gf-46xp, which has been closed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288CWE-305

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Technical Details · 2026-04-17: 104-1704-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40582 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before … https://www.cve.org/CVERecord?id=CVE-2026-40582

    Post summary

    A brief disclosure notes that CVE‑2026‑40582 affects ChurchCRM versions before 7.2.0 via the /api/public/user/login endpoint, but offers no technical details, PoC, or patch information.

    00000145
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40582: ChurchCRM: Aut... API endpoint sidesteps entire auth stack - password alone grants full API access, making 2FA and lockouts worthless #authbypass #apihack. https://zerodaysignal.com/vulnerability/CVE-2026-40582 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed authentication bypass vulnerability (CVE‑2026‑40582) in ChurchCRM permits password-only API access, undermining 2FA and lockout mechanisms.

    0000060
    218 followersView on X

Explore more