Junglewise Threat Intelligence

CVE-2026-39355: MGeurts Genealogy broken access control in TeamController

CVE-2026-39355 · Severity: critical · CVSS 9.9 · Published 2026-04-07

Executive brief

Genealogy is a PHP-based application used for managing family trees and collaborative team workspaces. A security flaw allows any logged-in user to take over ownership of other teams' workspaces without permission. An attacker could use this to gain full access to private family records, modify or delete data, and lock out the original owners, potentially leading to permanent data loss and privacy breaches.

Technical details

A broken access control vulnerability exists in the `TeamController::transferOwnership()` method of the Genealogy application. The application fails to perform authorization checks to verify if the requester is the current owner or even a member of the target team before updating the `user_id` field in the database. An authenticated attacker can bypass UI-level restrictions by sending a direct HTTP request to the ownership-transfer endpoint with a target team identifier. This results in a complete takeover of the team workspace, granting the attacker unrestricted access to all associated genealogy data. The issue is resolved in version 5.9.1.

Affected products

  • MGeurts genealogy < 5.9.1

Timeline

  • 2026-04-06: advisory: GitHub Security Advisory published by vendor
  • 2026-04-07: disclosed: CVE published to NVD
  • 2026-04-07: patched: Fix released in version 5.9.1

References