๐Ÿ” CVE Alert

CVE-2026-107856

MEDIUM 4.5

CiviForm: Trusted-Intermediary IDOR discloses any citizen's name and email

CVSS Score
4.5
EPSS Score
0.0%
EPSS Percentile
0th

CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0.

CWE CWE-639
Vendor civiform
Product civiform
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for civiform civiform

Be the first to know when new medium vulnerabilities affecting civiform civiform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

civiform / civiform
< 3.33.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/civiform/civiform/security/advisories/GHSA-qv7c-9hjr-9rv7 github.com: https://github.com/civiform/civiform/pull/13635 github.com: https://github.com/civiform/civiform/commit/ccfd84ff2d9ee6570a1b1524c7ae3a3732e1839e github.com: https://github.com/civiform/civiform/releases/tag/v3.33.0