PT-2026-95495 · Wacrm · Wacrm

CVE-2026-77240

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WACRM versions prior to 0.7.1
Description The software contains two security issues. First, the profiles update row-level security policy allows authenticated users to modify their own account role and account id variables, which can enable a user with viewer permissions to elevate their privileges or switch tenants to access and modify restricted resources. Second, the match ai knowledge fts() and match ai knowledge semantic() functions run as SECURITY DEFINER—meaning they execute with the privileges of the user who created them—and accept a caller-controlled p account id variable without verifying if the user is a member of that account. This allows authenticated non-members to read knowledge-base chunks belonging to other tenants.
Recommendations Update to the version containing commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77240
GHSA-FG5P-2QC3-JMXR

Affected Products

Wacrm