CVE-2026-44547

Source
https://cve.org/CVERecord?id=CVE-2026-44547
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44547.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44547
Aliases
  • GHSA-cwp8-rm8g-q5c9
Published
2026-05-12T22:30:15Z
Modified
2026-08-12T03:51:44Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2
Details

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/public/public-user.php by an unrelated PR before any 7.2.x tag was cut. Every shipped 7.2.x release therefore remains exploitable by the PoC published with the original advisory. This vulnerability is fixed in 7.3.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287",
        "CWE-304"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44547.json"
}
References

Affected packages

Git / github.com/churchcrm/crm

Affected ranges

Type
GIT
Repo
https://github.com/churchcrm/crm
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.2.0"
        },
        {
            "fixed": "7.3.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

7.*
7.2.0
7.2.1
7.2.2
7.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44547.json"