Vulnerability in WACRM Allows Unauthorized Access by Viewers
CVE-2026-77239

8.1HIGH

Key Information:

Vendor

Arnasdon

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-77239?

WACRM, a self-hostable CRM template for WhatsApp, has a security loophole in versions 0.7.0 and earlier that permits unauthorized users to manipulate workflows. Specifically, the issue lies in how account viewers are authenticated without applying the necessary role restrictions before executing critical database operations. This misconfiguration allows a user with viewer permissions to create, edit, activate, or delete automation flows, consequently leading to unauthorized modifications and detrimental actions within the system. The flaw was addressed in a subsequent commit that reinforced role-based access checks.

Affected Version(s)

wacrm <= 0.7.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.