CRITICAL
MGeurts
CVE published 2026-04-07
CVE-2026-39355
The Genealogy PHP application, version prior to 5.9.1, is vulnerable to a critical broken access control vulnerability. This vulnerability allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves, enabling complete takeover of other users' team workspaces and unrestricted access to all genealogy data associated with the compromised team. The vulnerability is fixed [truncated]