S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 4, 2026

CVE-2026-39339 Scanner

CVE-2026-39339 Scanner - Authentication Bypass vulnerability in ChurchCRM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-39339
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the request URL, leading to complete exposure of church member data and system information. This vulnerability is fixed in 7.1.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CRMby ChurchCRM
< 7.1.0
Updated Sep 10, 2026View on NVD →
Detail

ChurchCRM is a church management system used by religious organizations to manage member relationships, activities, and communication. It is widely implemented by churches for efficient management of congregation data and church operations. ChurchCRM is used by church administrators and leaders to streamline tasks related to event scheduling, contribution tracking, and generating various reports. This software allows users to automate several administrative tasks, reducing the burden on church staff and volunteers. It integrates various functionalities to ensure comprehensive data management, offering a digital approach for the church community. Due to its vital role in managing sensitive member data, maintaining the security of ChurchCRM is crucial.

The detected vulnerability in ChurchCRM is an Authentication Bypass that arises from improper API middleware URL handling. Specifically, it affects the AuthMiddleware component, allowing attackers to exploit URL injection vulnerabilities. This type of vulnerability enables unauthenticated users to gain access to endpoints that should be protected. Attackers are thus granted access to sensitive church member data and confidential system information without proper authentication. This weakness can particularly impact systems with versions of ChurchCRM prior to 7.1.0. It is essential to understand and address this vulnerability to prevent unauthorized access to critical church data.

Technically, the vulnerability roots from insufficient handling in the URL mechanism within the 'AuthMiddleware.php' file. Attackers can exploit this flaw by crafting a specific request URL that circumvents authentication controls. The vulnerable endpoint is accessible through inserting specific parameters within the request URL to bypass authentication checks. The vulnerability, identified by parameters such as 'api/public', directly impacts the API authentication mechanism. One key endpoint involves the '/api/persons/latest', which should be protected but becomes vulnerable due to URL manipulation. By exploiting this, attackers can successfully retrieve sensitive member information encapsulated in JSON format.

The successful exploitation of this authentication bypass vulnerability could lead to severe consequences for affected churches. It can result in unauthorized access to confidential member data, potentially leading to privacy violations. Attackers could gather personal information on church members, such as names and personal identifiers. Moreover, the exposure of system information could be leveraged for further cyberattacks or exploitation. The availability of sensitive data without restriction increases the risk for all individuals involved and potentially damages the reputation and trust in the church's management system.

REFERENCES

Solution Advice
  • Update ChurchCRM to version 7.1.0 or later to address the authentication bypass issue.
  • Regularly monitor and review API access logs for any unauthorized access attempts.
  • Implement strict input validation procedures to prevent URL injection vulnerabilities.
  • Enhance authentication mechanisms with multi-factor authentication for added security.
  • Conduct regular security audits and vulnerability assessments to detect potential threats early.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.