/Vulnerability Library

ChurchCRM - API Authentication Bypass via URL Injection

CVE-2026-39339
Verified

Description

ChurchCRM < 7.1.0 contains an authentication bypass caused by improper API middleware URL handling in ChurchCRM/Slim/Middleware/AuthMiddleware.php, letting unauthenticated attackers access protected API endpoints, exploit requires crafted request URL with 'api/public

Severity

Critical

CVSS Score

9.1

Exploit Probability

2%

Affected Product

churchcrm

Published Date

April 17, 2026

Template Author

akhilshekhar

CVE-2026-39339.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-39339
CWE ID:
cwe-284

References

https://github.com/ChurchCRM/CRM/security/advisories/GHSA-v3p2-mx78-pxhc

Remediation Steps

Update to version 7.1.0 or later.