CVE-2026-107856
Received Received - Intake

Information Disclosure in CiviForm Prior to 3.33.0

Vulnerability report for CVE-2026-107856, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
civiform civiform < 3.33.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CiviForm before version 3.33.0 has an authorization flaw in the GET /admin/tiDash/editClientForm/:accountId endpoint. While it verifies the requester is a Trusted Intermediary, it fails to confirm the citizen account belongs to the requester's trustedIntermediaryGroup. This allows enumeration of account IDs and exposure of citizen names and email addresses.

Detection Guidance

To detect this vulnerability, check if your CiviForm instance is running a version prior to 3.33.0. Inspect server logs for unusual GET requests to /admin/tiDash/editClientForm/:accountId and verify if unauthorized account data access occurred.

Impact Analysis

An authenticated Trusted Intermediary could exploit this to access personal data of citizens outside their assigned group. This includes names and email addresses, potentially leading to privacy breaches or misuse of sensitive information.

Compliance Impact

This vulnerability likely violates data protection regulations such as GDPR or HIPAA by enabling unauthorized access to personally identifiable information. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade CiviForm to version 3.33.0 or later immediately. Review access logs for suspicious activity and restrict Trusted Intermediary permissions until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107856. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart