Back to overview

CVE-2026-39355

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted access to all genealogy data associated with the compromised team. This vulnerability is fixed in 5.9.1.

Metadata

CVE ID
CVE-2026-39355
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-04-06 21:29 UTC
Published
2026-04-07 18:56 UTC
Last updated
2026-04-08 18:10 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
MGeurts / genealogy
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
MGeurts genealogy < 5.9.1
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (1)
Back to overview