Broken Access Control in Genealogy Application by MGeurts
CVE-2026-39355
10CRITICAL
What is CVE-2026-39355?
A broken access control vulnerability in the Genealogy PHP application, prior to version 5.9.1, allows authenticated users to unlawfully transfer ownership of arbitrary non-personal teams. This breach provides the potential for unauthorized access, enabling attackers to take over workspaces of other users and manipulate all associated genealogy data.
Affected Version(s)
genealogy < 5.9.1
