PatchSiren cyber security CVE debrief
CVE-2026-107856 civiform CVE debrief
CVE-2026-107856: CiviForm Trusted-Intermediary IDOR Vulnerability. An authenticated Trusted Intermediary can exploit this vulnerability to disclose sensitive information about citizens outside their group. The issue arises from inadequate verification of the requester's trustedIntermediaryGroup access to the requested citizen account in the GET /admin/tiDash/editClientForm/:accountId endpoint. This allows enumeration of accountId values and disclosure of citizen names and email addresses. Defenders should prioritize patching to version 3.33.0 and restrict access to the affected endpoint.
- Vendor
- civiform
- Product
- Unknown
- CVSS
- MEDIUM 4.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders of CiviForm installations should assess exposure and apply the patch in version 3.33.0. System administrators and security teams responsible for government benefits programs using CiviForm should verify their version and restrict access to the affected endpoint if patching is not immediately feasible.
Why it matters
CVE-2026-107856 is a medium-severity vulnerability in CiviForm that allows an authenticated Trusted Intermediary to disclose sensitive information about citizens outside their group. Defenders should prioritize patching to version 3.33.0 and restrict access to the affected endpoint. Evidence is limited to official CVE and source item records.
- Enumeration of accountId values by an authenticated Trusted Intermediary
- Disclosure of citizen names and email addresses outside the intermediary's group
- Potential for data misuse by insiders with Trusted Intermediary access
- Verification of patch application and endpoint access controls
Technical summary
Prior to version 3.33.0, CiviForm's GET /admin/tiDash/editClientForm/:accountId endpoint did not properly verify that the requester's trustedIntermediaryGroup had access to the requested citizen account. This allowed an authenticated Trusted Intermediary to read the applicant display name, including the citizen's name and email address, for accounts outside their group. The issue is fixed in version 3.33.0, which properly validates the requester's access to the citizen account. Defenders should prioritize patching to this version.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the patch in version 3.33.0
- Restrict access to the /admin/tiDash/editClientForm endpoint
- Monitor for suspicious activity on the affected system
- Verify patch application and endpoint access controls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability. The NVD entry is currently UNCHANGED. Evidence is limited to official CVE and source item records. Defenders should verify patch application and endpoint access controls. The vulnerability allows an authenticated Trusted Intermediary to read applicant display names, including citizen names and email addresses, for accounts outside their group.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107856 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107856
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107856 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107856
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CiviForm: Trusted-Intermediary IDOR discloses any citizen's name and email
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107856.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/civiform/civiform/security/advisories/GHSA-qv7c-9hjr-9rv7
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/civiform/civiform/pull/13635
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/civiform/civiform/commit/ccfd84ff2d9ee6570a1b1524c7ae3a3732e1839e
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/civiform/civiform/releases/tag/v3.33.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.