External risk intelligence

WACRM privilege escalation and unauthorized knowledge access vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-77240

The product is a self-hostable CRM template designed for integration with WhatsApp. Such applications are typically deployed as internet-facing web services to handle incoming messaging webhooks and provide user interfaces for customer relationship management, making them common targets for public network reachability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in WACRM, a self-hostable CRM template for WhatsApp, that could allow authenticated users to gain unauthorized access and modify data within other tenants. The issue stems from flawed access control policies within the database's security configurations. While specific business impact is uncertain without knowing deployment specifics, the potential for data compromise warrants attention.

  • Unauthorized access and data modification risks.
  • Affects self-hosted WhatsApp CRM templates.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with existing access to WACRM could exploit this vulnerability by crafting specific requests to manipulate user roles or access sensitive data. The attacker would first need to authenticate as a regular user. By targeting a flawed security policy or a function that bypasses member checks, they could then elevate their privileges or view data belonging to other tenants, potentially leading to unauthorized modification or exposure of tenant resources and AI knowledge.

  • Authenticated user required for access.
  • Manipulate roles or bypass access checks.
  • Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

Authenticated users of WACRM could gain unauthorized access to or modify another tenant's data. This is possible when specific database policies are bypassed, allowing users to self-promote or change their tenant affiliation. This could lead to unauthorized viewing or alteration of sensitive customer information within different accounts.

  • Tenant data and user roles.
  • Authenticated users can exploit policy flaws.
  • Unauthorized access and modification of data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining ownership for WACRM, a self-hostable WhatsApp CRM template, requires understanding its deployment. Application owners are likely responsible for the core CRM functionality, while infrastructure or platform teams may manage the underlying Supabase or hosting environment. The first step is to identify all WACRM instances, assess their exposure and criticality, and then engage the accountable owners to plan remediation.

  • Application owners, platform teams.
  • Confirm instance reachability and criticality.
  • Plan maintenance, coordinate with vendors.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WACRM?

WACRM is a template for building custom customer relationship management systems that integrate directly with WhatsApp. Because it is self-hosted, organizations use it to manage messaging workflows, customer interactions, and AI-driven knowledge bases locally rather than relying on a third-party SaaS provider.

What is the vulnerability in CVE-2026-77240?

This vulnerability is an Authorization Bypass, classified as CWE-639. It occurs because the software's database settings fail to verify that a user has permission to perform certain actions. Consequently, an authenticated user can manipulate their own account settings to gain higher privileges or trick the system into revealing sensitive data belonging to other tenants.

How does an attacker trigger this issue?

An attacker must already have an authenticated user account on the WACRM instance to initiate the exploit. Simply browsing the site without logging in does not trigger the bug. Once authenticated, the attacker sends crafted requests that exploit flaws in database policies, allowing them to bypass identity checks or modify their account role.

Do I need to worry if my WACRM instance is internal?

According to Halo Surface Signal, WACRM is typically deployed as an internet-facing service to handle external WhatsApp webhooks, which increases the likelihood of public reachability. If your instance is exposed to the internet, the risk of unauthorized access is higher, but even internal instances are vulnerable if an attacker gains any level of authenticated access to your network.

How do I start addressing CVE-2026-77240?

Begin by identifying all running instances of WACRM within your environment. Once mapped, coordinate with your application and infrastructure teams to verify the version in use. The vulnerability is resolved in the source code via a specific commit, so planning an update or applying the provided patch to your database migration scripts is the necessary path forward.

References