Impact
The flaw lies in service‑role database routes that omit an explicit role validation (CWE‑285). As a result, any user with viewer privileges can bypass row‑level security and write data with elevated permissions. A viewer can add, edit, activate or delete workflow flows, create active automations, and trigger outbound WhatsApp messages. The attacker can delete critical workflows, modify automation logic, and send messages from an account that should be read‑only.
Affected Systems
The vulnerability applies to all releases of the self‑hosted WACRM CRM template up to and including version 0.7.0. Versions 0.7.1 and later incorporate the fix introduced by commit 03e851b, which restores proper role checks on service‑role routes.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score is not available, which suggests no publicly known exploitation prevalence yet; however, any authenticated viewer can exploit it by sending crafted HTTP requests to the affected API endpoints. The vulnerability is not listed in CISA KEV, indicating no confirmed exploit in the wild at this time. The likely attack vector is a web‑based request from an account with viewer permissions, and the attacker requires no additional privileges beyond those already possessed by the target user.
OpenCVE Enrichment