Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39331

27
FAUCET Score

CVE-2026-39331 is a broken access control vulnerability affecting ChurchCRM versions prior to 7.1.0, an open-source church management system. Authenticated API users can manipulate family records and trigger associated actions such as verification, activation, deactivation, and geocoding without possessing the required EditRecords privilege, simply by modifying the familyId parameter in API requests. The vulnerability exposes multiple endpoints lacking proper role-based access control. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network attack vector and low attack complexity, requiring only low-level user authentication and no user interaction. The impact is significant, enabling attackers to modify system state and integrity through unauthorized activation/deactivation of family records, spam verification emails, and unauthorized status changes, though confidentiality is not directly affected. There is currently no indication of active exploitation in the wild, with an EPSS score of 0.00041 placing it in the lower percentile of exploited vulnerabilities. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code availability is documented. The moderate FAUCET Risk Score of 50.0/100 suggests this remains a community concern requiring attention, particularly for organizations deploying ChurchCRM instances that should upgrade to version 7.1.0 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.1.0CPE matchmatch criteria
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
12.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 2nd percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / ChurchCRM/CRM/security/advisories/GHSA-vwh8-x823-wjc5
Third Party Advisory