logo

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

ID: bc159a55-40bf-5d29-9e35-7b730799e2c1

STIX ID: report--bc159a55-40bf-5d29-9e35-7b730799e2c1

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Nate Nelson

...
...

A reportedly insecure API endpoint in the Vatican's Click to Pray service allowed unauthenticated access to sequential user records, leaking names, email addresses, country codes, account status and admin flags for over 700,000 accounts; the IDOR (broken access control) was discovered by a white-hat researcher and independently confirmed, posing a large-scale PII exposure and enabling easy mass phishing or impersonation attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.