CVE-2026-39339: ChurchCRM - API Authentication Bypass via URL Injection

HoneyLabs honeypots recorded 1 probes matching CVE-2026-39339 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /api/persons/latest
  • /api/persons/latest?bypass=/api/public

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2141Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited11

Captured requests

  • /api/persons/latest?bypass=/api/public

CVE report

CVE report

Open a specific CVE from the CVE tracker.