CVE-2026-40480 | ChurchCRM up to 7.1.x /api/person/ canEditPerson authorization (ID 8617 / EUVD-2026-23589)
A vulnerability was found in ChurchCRM up to 7.1.x. It has been declared as problematic. This affects the function canEditPerson of the file /api/person/. The manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-40480. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.