OVERVIEW CVE-2026-40485 is a user enumeration vulnerability affecting ChurchCRM, an open-source church management system, in versions prior to 7.2.0. The public API login endpoint at /api/public/user/login returns distinguishable HTTP response codes (404 for non-existent users, 401 for valid users with incorrect passwords), allowing unauthenticated attackers to systematically identify valid usernames without rate limiting or account lockout protections. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.3 (Medium) with a network-based attack vector requiring no privileges or user interaction. While attack complexity is low and exploitation is straightforward, the impact is limited to low confidentiality loss through username enumeration with no integrity or availability impacts. The vulnerability primarily enables reconnaissance for downstream attacks rather than direct system compromise. EXPLOITATION STATUS There is no evidence of active exploitation, with the vulnerability marked as inactive on the KEV catalog and showing minimal EPSS score of 0.000120000. No public exploit code or significant community attention has been reported. The availability of a patched version 7.2.0 provides a clear remediation path for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ChurchCRM | CRM | < 7.2.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.