Vulnerability in WACRM Allows Unauthorized Access by Viewers
CVE-2026-77239
8.1HIGH
What is CVE-2026-77239?
WACRM, a self-hostable CRM template for WhatsApp, has a security loophole in versions 0.7.0 and earlier that permits unauthorized users to manipulate workflows. Specifically, the issue lies in how account viewers are authenticated without applying the necessary role restrictions before executing critical database operations. This misconfiguration allows a user with viewer permissions to create, edit, activate, or delete automation flows, consequently leading to unauthorized modifications and detrimental actions within the system. The flaw was addressed in a subsequent commit that reinforced role-based access checks.
Affected Version(s)
wacrm <= 0.7.0
