Row-Level Security Flaw in WACRM CRM Template for WhatsApp
CVE-2026-77240

9.9CRITICAL

Key Information:

Vendor

Arnasdon

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-77240?

The WACRM CRM template for WhatsApp is susceptible to a serious security flaw that enables authenticated users to exploit weaknesses in the row-level security policies. In versions 0.7.0 and earlier, users can modify their account roles and tenant identifiers, potentially allowing unauthorized access to sensitive tenant resources. Additionally, issues in the ai knowledge modules allow non-member users to access knowledge-base content of other tenants without proper checks. This breach could facilitate unauthorized data manipulation and expose sensitive information, leading to significant security risks.

Affected Version(s)

wacrm <= 0.7.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.