PT-2026-47450 · Wacrm · Wacrm

·

CVE-2026-49141

·

Published

2026-06-08

·

Updated

2026-07-23

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions WACRM versions prior to commit 73041bf
Description An authorization bypass exists in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants. By providing an arbitrary contact id in the body of a 'POST' request, attackers can bypass tenant ownership verification. This is achieved by exploiting the service-role client, which bypasses row-level security (a security feature that restricts which rows of data a user can see or modify based on their identity), enabling the modification of victim contact fields such as name, email, and company across tenant boundaries using a known contact UUID.
Recommendations Update WACRM to commit 73041bf or a later version.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49141

Affected Products

Wacrm