Impact
This vulnerability in WACRM allows an authenticated user to bypass mandatory data access controls within the database layer. By exploiting the rows‑level security policy in supabase/migrations/017_account_sharing.sql, a user can alter their own account_role and account_id fields, effectively promoting themselves to a higher privilege level or moving them into another tenant. In addition, the functions match_ai_knowledge_fts and match_ai_knowledge_semantic, both defined with SECURITY DEFINER and lacking a membership check, enable an authenticated non‑member to read another tenant’s knowledge‑base content. These flaws can compromise confidentiality, integrity, and availability of tenant data, and permit a user to modify or leak sensitive information belonging to other tenants.
Affected Systems
The affected product is the self‑hostable WhatsApp CRM template developed by ArnasDon (ArnasDon:wacrm). All releases version 0.7.0 and earlier are vulnerable. Users running these versions should verify their installed version and consider upgrading to a patched release.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. Because the vulnerability requires an authenticated user, the attack vector is likely local or authenticated network access rather than remote exploitation. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, given the high CVSS metric and the nature of the privilege escalation, the risk of exploitation is significant for any organization deploying the affected versions. An attacker who can create or compromise an account on the system could gain unauthorized tenant access and read or modify confidential data.
OpenCVE Enrichment