PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107856 civiform CVE debrief

CVE-2026-107856: CiviForm Trusted-Intermediary IDOR Vulnerability. An authenticated Trusted Intermediary can exploit this vulnerability to disclose sensitive information about citizens outside their group. The issue arises from inadequate verification of the requester's trustedIntermediaryGroup access to the requested citizen account in the GET /admin/tiDash/editClientForm/:accountId endpoint. This allows enumeration of accountId values and disclosure of citizen names and email addresses. Defenders should prioritize patching to version 3.33.0 and restrict access to the affected endpoint.

Vendor
civiform
Product
Unknown
CVSS
MEDIUM 4.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders of CiviForm installations should assess exposure and apply the patch in version 3.33.0. System administrators and security teams responsible for government benefits programs using CiviForm should verify their version and restrict access to the affected endpoint if patching is not immediately feasible.

Why it matters

CVE-2026-107856 is a medium-severity vulnerability in CiviForm that allows an authenticated Trusted Intermediary to disclose sensitive information about citizens outside their group. Defenders should prioritize patching to version 3.33.0 and restrict access to the affected endpoint. Evidence is limited to official CVE and source item records.

  • Enumeration of accountId values by an authenticated Trusted Intermediary
  • Disclosure of citizen names and email addresses outside the intermediary's group
  • Potential for data misuse by insiders with Trusted Intermediary access
  • Verification of patch application and endpoint access controls

Technical summary

Prior to version 3.33.0, CiviForm's GET /admin/tiDash/editClientForm/:accountId endpoint did not properly verify that the requester's trustedIntermediaryGroup had access to the requested citizen account. This allowed an authenticated Trusted Intermediary to read the applicant display name, including the citizen's name and email address, for accounts outside their group. The issue is fixed in version 3.33.0, which properly validates the requester's access to the citizen account. Defenders should prioritize patching to this version.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the patch in version 3.33.0
  • Restrict access to the /admin/tiDash/editClientForm endpoint
  • Monitor for suspicious activity on the affected system
  • Verify patch application and endpoint access controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability. The NVD entry is currently UNCHANGED. Evidence is limited to official CVE and source item records. Defenders should verify patch application and endpoint access controls. The vulnerability allows an authenticated Trusted Intermediary to read applicant display names, including citizen names and email addresses, for accounts outside their group.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107856 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107856

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107856 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107856

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CiviForm: Trusted-Intermediary IDOR discloses any citizen's name and email

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107856.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/civiform/civiform/security/advisories/GHSA-qv7c-9hjr-9rv7

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/civiform/civiform/pull/13635

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/civiform/civiform/commit/ccfd84ff2d9ee6570a1b1524c7ae3a3732e1839e

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/civiform/civiform/releases/tag/v3.33.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.