Description
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypasses row-level security. In src/app/api/flows/[id]/route.ts, src/app/api/flows/[id]/activate/route.ts, and src/app/api/flows/route.ts, a viewer can create, edit, activate, or delete flows because membership-only checks are followed by service-role writes. In src/app/api/automations/route.ts and src/app/api/automations/engine/route.ts, a viewer can create active automations and trigger outbound WhatsApp actions without the role required by the underlying write policies. This can permit unauthorized workflow changes, destructive flow deletion, and outbound actions from a role intended to be read-only. This vulnerability is fixed with commit 03e851bea56dcf6bb21ff1b80ba531372bf3269f.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Unauthorized Operations
Action: Apply Patch
AI Analysis

Impact

The flaw lies in service‑role database routes that omit an explicit role validation (CWE‑285). As a result, any user with viewer privileges can bypass row‑level security and write data with elevated permissions. A viewer can add, edit, activate or delete workflow flows, create active automations, and trigger outbound WhatsApp messages. The attacker can delete critical workflows, modify automation logic, and send messages from an account that should be read‑only.

Affected Systems

The vulnerability applies to all releases of the self‑hosted WACRM CRM template up to and including version 0.7.0. Versions 0.7.1 and later incorporate the fix introduced by commit 03e851b, which restores proper role checks on service‑role routes.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the EPSS score is not available, which suggests no publicly known exploitation prevalence yet; however, any authenticated viewer can exploit it by sending crafted HTTP requests to the affected API endpoints. The vulnerability is not listed in CISA KEV, indicating no confirmed exploit in the wild at this time. The likely attack vector is a web‑based request from an account with viewer permissions, and the attacker requires no additional privileges beyond those already possessed by the target user.

Generated by OpenCVE AI on September 19, 2026 at 14:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WACRM to version 0.7.1 or later, which contains the commit that restores role checks.
  • If an immediate update is not possible, refuse viewer access to the flows and automation API routes or implement an application‑level middleware that enforces the required agent role before allowing any service‑role database writes.
  • Monitor logs for unauthorized flow or automation modifications and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 19, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Arnasdon
Arnasdon wacrm
Vendors & Products Arnasdon
Arnasdon wacrm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypasses row-level security. In src/app/api/flows/[id]/route.ts, src/app/api/flows/[id]/activate/route.ts, and src/app/api/flows/route.ts, a viewer can create, edit, activate, or delete flows because membership-only checks are followed by service-role writes. In src/app/api/automations/route.ts and src/app/api/automations/engine/route.ts, a viewer can create active automations and trigger outbound WhatsApp actions without the role required by the underlying write policies. This can permit unauthorized workflow changes, destructive flow deletion, and outbound actions from a role intended to be read-only. This vulnerability is fixed with commit 03e851bea56dcf6bb21ff1b80ba531372bf3269f.
Title WACRM: Service-role routes missing a role check
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T19:56:33.123Z

Reserved: 2026-08-20T19:02:23.415Z

Link: CVE-2026-77239

cve-icon Vulnrichment

Updated: 2026-09-18T19:56:29.242Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:00.200

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-77239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses