WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
History

Tue, 09 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Arnasdon
Arnasdon wacrm
Vendors & Products Arnasdon
Arnasdon wacrm

Mon, 08 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Description WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Title WACRM Authorization Bypass via Automation Engine Endpoint
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-06-08T19:13:16.960Z

Updated: 2026-06-09T13:19:07.106Z

Reserved: 2026-05-27T17:40:12.739Z

Link: CVE-2026-49141

cve-icon Vulnrichment

Updated: 2026-06-09T13:19:03.136Z

cve-icon NVD

Status : Deferred

Published: 2026-06-08T20:17:01.997

Modified: 2026-06-09T13:51:18.770

Link: CVE-2026-49141

cve-icon Redhat

No data.