Data Exposure Vulnerability in CiviForm by CiviForm
CVE-2026-107856

4.5MEDIUM

Key Information:

Vendor

Civiform

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107856?

CiviForm, a platform for simplifying government benefits applications, has a vulnerability that allows authenticated Trusted Intermediaries to access user data beyond their permission scope. Specifically, prior to version 3.33.0, the system fails to adequately verify if a citizen account resides within a Trusted Intermediary's group during account lookups. As a result, it exposes sensitive information such as applicant names and email addresses for users not associated with the Trusted Intermediary, posing a potential risk to user privacy. This issue has been addressed in version 3.33.0.

Affected Version(s)

civiform < 3.33.0

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.