Data Exposure Vulnerability in CiviForm by CiviForm
CVE-2026-107856
4.5MEDIUM
What is CVE-2026-107856?
CiviForm, a platform for simplifying government benefits applications, has a vulnerability that allows authenticated Trusted Intermediaries to access user data beyond their permission scope. Specifically, prior to version 3.33.0, the system fails to adequately verify if a citizen account resides within a Trusted Intermediary's group during account lookups. As a result, it exposes sensitive information such as applicant names and email addresses for users not associated with the Trusted Intermediary, posing a potential risk to user privacy. This issue has been addressed in version 3.33.0.
Affected Version(s)
civiform < 3.33.0
