LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-49141

Published
CVSS7.1
Severityhigh
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N

Description

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-49141

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-49141.