Row-Level Security Flaw in WACRM CRM Template for WhatsApp
CVE-2026-77240
9.9CRITICAL
What is CVE-2026-77240?
The WACRM CRM template for WhatsApp is susceptible to a serious security flaw that enables authenticated users to exploit weaknesses in the row-level security policies. In versions 0.7.0 and earlier, users can modify their account roles and tenant identifiers, potentially allowing unauthorized access to sensitive tenant resources. Additionally, issues in the ai knowledge modules allow non-member users to access knowledge-base content of other tenants without proper checks. This breach could facilitate unauthorized data manipulation and expose sensitive information, leading to significant security risks.
Affected Version(s)
wacrm <= 0.7.0
