PatchSiren

MGeurts CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL MGeurts CVE published 2026-04-07

CVE-2026-39355

The Genealogy PHP application, version prior to 5.9.1, is vulnerable to a critical broken access control vulnerability. This vulnerability allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves, enabling complete takeover of other users' team workspaces and unrestricted access to all genealogy data associated with the compromised team. The vulnerability is fixed [truncated]