CVE-2026-40581
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records ...
Affects 0 products across 2 vendors.
Web application does not verify that a request was intentionally sent by the authenticated user.
Software does not check whether an authenticated actor has permission for the requested operation.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
ChurchCRM versions prior to 7.2.0 are vulnerable to unauthorized deletion of family records due to a lack of CSRF protection on the SelectDelete.php endpoint.
BSID: BS-2026-GLOBAL-265460-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-40581?
What is the CVSS score for CVE-2026-40581?
Is CVE-2026-40581 actively exploited?
How do I remediate CVE-2026-40581?
What systems are affected by CVE-2026-40581?
| CVE ID | CVE-2026-40581 |
|---|---|
| BSID | BS-2026-GLOBAL-265460-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
| Published | 2026-04-18 |
| Last Modified | 2026-04-20 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a malicious page that, when visited by an authenticated administrator, silently triggers deletion of targeted family records including associated notes, pledges, persons, and property data without any user interaction. This issue has been fixed in version 7.2.0.
Source: NIST NVD / MITRE CVE Database
An attacker can craft a malicious web page that, when visited by an authenticated administrator, can silently trigger the deletion of family records via a GET request to the SelectDelete.php endpoint without proper CSRF token validation.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Associated | — | — |
| Churchcrm | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | c78aeb076426a9dfda64f6d0c51549a83032f3fe8f0a9d52b201e3096e3be308b5117ffae707b320809f239c8a38e5599f7a179a59b69541cfc9faad22224f55 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →