{"id":"CVE-2026-77240","published":"2026-09-18T17:17:00.360","lastModified":"2026-09-23T20:17:15.427","description":"WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and then access or modify tenant resources. Separately, match_ai_knowledge_fts and match_ai_knowledge_semantic in supabase/migrations/030_ai_knowledge.sql run as SECURITY DEFINER, accept a caller-controlled p_account_id, and omit an is_account_member check, allowing an authenticated non-member to read another tenant's knowledge-base chunks. This vulnerability is fixed with commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ArnasDon/wacrm/commit/e01f7ed37184f972ace8fb2da5c3e37e56a6050f","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/pull/350","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/security/advisories/GHSA-fg5p-2qc3-jmxr","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/security/advisories/GHSA-fg5p-2qc3-jmxr","tags":[]}],"exploitRefs":[{"url":"https://github.com/ArnasDon/wacrm/commit/e01f7ed37184f972ace8fb2da5c3e37e56a6050f","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/pull/350","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/security/advisories/GHSA-fg5p-2qc3-jmxr","tags":[]},{"url":"https://github.com/ArnasDon/wacrm/security/advisories/GHSA-fg5p-2qc3-jmxr","tags":[]}],"hasPoc":true,"ai":{"summary":"Authenticated users can modify their own account_role and account_id, and an authenticated non-member can read another tenant's knowledge-base chunks, potentially leading to unauthorized access and data modification.","exploitability":"Exploitation is relatively straightforward for authenticated users and requires an authenticated non-member with access to the affected migration scripts.","blast_radius":"If exploited, this could result in unauthorized access to tenant resources and data, compromising the integrity and confidentiality of the system.","remediation":"Upgrade to version 0.7.1 or later, which includes the necessary fixes for these vulnerabilities.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","data-leak","sql","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:57:50.509Z"}}