logo

Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts

ID: f71f7d46-2217-5852-992e-68c6070a7b2e

STIX ID: report--f71f7d46-2217-5852-992e-68c6070a7b2e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Mayura Kathir

...
...

A critical IDOR (insecure direct object reference) vulnerability in the Vatican’s Click to Pray web and mobile platforms allowed unauthenticated enumeration of sequential user IDs, exposing PII for more than 700,000 users — including full names, emails, country identifiers, account status, and privilege levels (notably staff/admin accounts). The flaw enabled trivial mass data harvesting and would facilitate highly targeted phishing or impersonation campaigns; attempts to coordinate remediation were reportedly unsuccessful at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.