Junglewise Threat Intelligence

CVE-2026-58408: ChurchCRM broken access control in CSVCreateFile.php export

CVE-2026-58408 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: ChurchCRM. Vendors: ChurchCRM.

Executive brief

ChurchCRM, an open-source church management system, contains a security flaw that allows users with minimal access rights to download the entire member directory. By bypassing the intended administrative interface, a low-privileged user can export a file containing sensitive personal information for every member and family in the database, including names, addresses, phone numbers, and dates of birth. This unauthorized access could lead to significant privacy breaches, identity theft risks for members, and potential regulatory compliance issues for the organization.

Technical details

A broken access control vulnerability exists in ChurchCRM's CSV export functionality. The 'CSVCreateFile.php' endpoint relies on a legacy authorization gate in 'PageInit.php' that incorrectly grants access to any user possessing any single administrative-related permission (such as adding records or managing groups), rather than requiring full administrator rights or a specific export permission. An authenticated attacker with low-level privileges can bypass the intended UI restrictions by sending a direct POST request to the export endpoint. This allows for the bulk exfiltration of Personally Identifiable Information (PII) for all records in the database. The issue is addressed in version 7.4.0 by implementing stricter authorization checks.

Affected products

  • ChurchCRM ChurchCRM < 7.4.0

Timeline

  • 2026-06-18: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date
  • 2026-07-13: patched: Fix confirmed in version 7.4.0

References

Related threats