logo

Vatican Click to Pray API Flaw Exposes 700K Users

ID: d77015a5-5182-5bf1-a2a1-e1035e9b54c7

STIX ID: report--d77015a5-5182-5bf1-a2a1-e1035e9b54c7

Feed Name: CyberNexora News

Threat Score
65/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Debolina Barik

...
...

The report details an Insecure Direct Object Reference (IDOR) in the Vatican's Click to Pray API that reportedly allowed unauthenticated access to potentially more than 700,000 user records (first/last names, email addresses, country identifiers, account status and roles); it covers discovery by an ethical hacker, independent verification, the technical root cause (broken access control), the likely risks (targeted phishing, credential stuffing, impersonation, reputational and regulatory impact), and prescribes remediation such as enforcing object-level authorization, API security testing, MFA, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.