Description
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and then access or modify tenant resources. Separately, match_ai_knowledge_fts and match_ai_knowledge_semantic in supabase/migrations/030_ai_knowledge.sql run as SECURITY DEFINER, accept a caller-controlled p_account_id, and omit an is_account_member check, allowing an authenticated non-member to read another tenant's knowledge-base chunks. This vulnerability is fixed with commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in WACRM allows an authenticated user to bypass mandatory data access controls within the database layer. By exploiting the rows‑level security policy in supabase/migrations/017_account_sharing.sql, a user can alter their own account_role and account_id fields, effectively promoting themselves to a higher privilege level or moving them into another tenant. In addition, the functions match_ai_knowledge_fts and match_ai_knowledge_semantic, both defined with SECURITY DEFINER and lacking a membership check, enable an authenticated non‑member to read another tenant’s knowledge‑base content. These flaws can compromise confidentiality, integrity, and availability of tenant data, and permit a user to modify or leak sensitive information belonging to other tenants.

Affected Systems

The affected product is the self‑hostable WhatsApp CRM template developed by ArnasDon (ArnasDon:wacrm). All releases version 0.7.0 and earlier are vulnerable. Users running these versions should verify their installed version and consider upgrading to a patched release.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity. Because the vulnerability requires an authenticated user, the attack vector is likely local or authenticated network access rather than remote exploitation. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, given the high CVSS metric and the nature of the privilege escalation, the risk of exploitation is significant for any organization deploying the affected versions. An attacker who can create or compromise an account on the system could gain unauthorized tenant access and read or modify confidential data.

Generated by OpenCVE AI on September 19, 2026 at 12:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version that includes commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f or later; this patch removes the dangerous row‑level security bypass and corrects the missing membership check in the AI knowledge functions.
  • Ensure that database functions which run with SECURITY DEFINER are audited and that any caller‑controlled parameters are properly validated against the user’s membership status; implement an explicit is_account_member check before granting data access.
  • Review and correct any remaining row‑level security policies to guarantee that authenticated users can only modify data that belongs to their own tenant, and audit logs for unauthorized changes to account_role or account_id.

Generated by OpenCVE AI on September 19, 2026 at 12:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Arnasdon
Arnasdon wacrm
Vendors & Products Arnasdon
Arnasdon wacrm

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and then access or modify tenant resources. Separately, match_ai_knowledge_fts and match_ai_knowledge_semantic in supabase/migrations/030_ai_knowledge.sql run as SECURITY DEFINER, accept a caller-controlled p_account_id, and omit an is_account_member check, allowing an authenticated non-member to read another tenant's knowledge-base chunks. This vulnerability is fixed with commit e01f7ed37184f972ace8fb2da5c3e37e56a6050f.
Title WACRM: Database-layer authorization bypasses
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:04:56.356Z

Reserved: 2026-08-20T19:02:23.415Z

Link: CVE-2026-77240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:00.360

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-77240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key