logo

Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw

ID: 2de2e42c-4af7-55d6-9fc6-bdb2e9e1fe1a

STIX ID: report--2de2e42c-4af7-55d6-9fc6-bdb2e9e1fe1a

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Tushar Subhra Dutta

...
...

## Executive summary An IDOR vulnerability in the Click to Pray application's unauthenticated API exposed personal records for roughly 700,000+ users (names, emails, passwords, country and roles), enabling bulk harvesting and increasing risk of targeted phishing and impersonation; the report describes discovery, testing, and mitigation recommendations and includes the ClicktoPray domain as an IoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.