CVE-2026-35567
8.8ChurchCRM · ChurchCRM
ChurchCRM, an open-source church management platform, contains an unspecified vulnerability that requires further technical clarification to determine the precise impact and exploitation vector.
Executive summary
An unspecified security vulnerability in ChurchCRM poses a significant risk to organizational data integrity and system security, warranting immediate investigation and remediation.
Vulnerability
The vulnerability details for this entry are currently insufficient to identify the specific flaw or the required authentication level for exploitation.
Business impact
The CVSS score of 8.8 indicates a high-severity risk that could lead to significant unauthorized access or system compromise. If left unaddressed, this vulnerability may allow attackers to manipulate sensitive member data, disrupt administrative operations, or gain unauthorized control over the management system, leading to potential reputational and operational damage.
Remediation
Immediate Action: Organizations should monitor the official ChurchCRM repository and security advisories for the release of a patch or specific version guidance.
Proactive Monitoring: Security teams should review application and database access logs for unusual patterns, unauthorized login attempts, or anomalous administrative activity.
Compensating Controls: Deploy a Web Application Firewall with strict rule sets to inspect incoming traffic and block suspicious requests targeting the ChurchCRM web interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score, this vulnerability should be treated with urgency despite the current lack of specific technical details. Administrators must prioritize regular check-ins with official vendor channels and apply security updates as soon as they are made available to protect the integrity of the church management environment.