OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-77240

CRITICAL · CVSS 9.9 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

In versions 0.7.0 and earlier of WACRM, a critical vulnerability allows authenticated users to manipulate their account roles and IDs, enabling unauthorized access to tenant resources. Additionally, flaws in the AI knowledge modules permit non-member users to read knowledge-base content from other tenants. Organizations using affected versions should prioritize remediation to prevent potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77240
Severity
CRITICAL
CVSS
9.9
EPSS
0.35%

Original NVD Description

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and then access or modify tenant resources. Separately, match_ai_knowledge_fts and match_ai_knowledge_semantic in supabase/migrations/030_ai_knowledge.sql run as SECURITY DEFINER, accept a caller-controlled p_account_id, and omit an is_account_member check, allowing an authenticated non-member to read another tenant's knowledge-base chunks. This vulnerability is fixed with commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f.