PT-2026-95494 · Wacrm · Wacrm

CVE-2026-77239

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WACRM versions prior to 0.7.1
Description Account viewers can perform unauthorized actions because flow and automation write routes fail to enforce the agent role before utilizing a service-role database client that bypasses row-level security (a security feature that restricts which rows of data a user can access). This allows a viewer to create, edit, activate, or delete flows via the endpoints '/api/flows/[id]', '/api/flows/[id]/activate', and '/api/flows'. Additionally, viewers can create active automations and trigger outbound WhatsApp actions through the endpoints '/api/automations' and '/api/automations/engine'. This flaw enables unauthorized workflow modifications, destructive deletion of flows, and the execution of outbound actions by a role intended to be read-only.
Recommendations Update to a version containing commit 03e851bea56dcf6bb21ff1b80ba531372bf3269f.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77239
GHSA-34Q7-FV77-625J

Affected Products

Wacrm