PatchSiren

civiform CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM civiform CVE published 2026-10-09

CVE-2026-107856

CVE-2026-107856: CiviForm Trusted-Intermediary IDOR Vulnerability. An authenticated Trusted Intermediary can exploit this vulnerability to disclose sensitive information about citizens outside their group. The issue arises from inadequate verification of the requester's trustedIntermediaryGroup access to the requested citizen account in the GET /admin/tiDash/editClientForm/:accountId endpoint. This allows [truncated]