CVE-2026-39331 is a broken access control vulnerability affecting ChurchCRM versions prior to 7.1.0, an open-source church management system. Authenticated API users can manipulate family records and trigger associated actions such as verification, activation, deactivation, and geocoding without possessing the required EditRecords privilege, simply by modifying the familyId parameter in API requests. The vulnerability exposes multiple endpoints lacking proper role-based access control. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network attack vector and low attack complexity, requiring only low-level user authentication and no user interaction. The impact is significant, enabling attackers to modify system state and integrity through unauthorized activation/deactivation of family records, spam verification emails, and unauthorized status changes, though confidentiality is not directly affected. There is currently no indication of active exploitation in the wild, with an EPSS score of 0.00041 placing it in the lower percentile of exploited vulnerabilities. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code availability is documented. The moderate FAUCET Risk Score of 50.0/100 suggests this remains a community concern requiring attention, particularly for organizations deploying ChurchCRM instances that should upgrade to version 7.1.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.1.0CPE matchmatch criteria | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.