Authorization Bypass in WACRM Automation Engine Allows Tenant Access
CVE-2026-49141
5.1MEDIUM
What is CVE-2026-49141?
A vulnerability in the automation engine of WACRM allows authenticated attackers to manipulate contacts across different tenants without proper ownership verification. By submitting a POST request with a user-controlled contact_id, attackers can bypass row-level security and modify contact information, including the name, email, and company, of other tenants. This issue poses significant risks to tenant data protection and highlights a critical need for enhanced security measures.
Affected Version(s)
wacrm 0
