ChurchCRM - API Authentication Bypass via URL Injection
CVE-2026-39339
Verified
Description
ChurchCRM < 7.1.0 contains an authentication bypass caused by improper API middleware URL handling in ChurchCRM/Slim/Middleware/AuthMiddleware.php, letting unauthenticated attackers access protected API endpoints, exploit requires crafted request URL with 'api/public
Severity
Critical
CVSS Score
9.1
Exploit Probability
2%
Affected Product
churchcrm
Published Date
April 17, 2026
Template Author
akhilshekhar
CVE-2026-39339.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-39339
CWE ID:
cwe-284
Remediation Steps
Update to version 7.1.0 or later.