CVE-2026-39355
Genealogy is a PHP family‑tree application that had a broken access control flaw before version 5.9.1. The flaw let any logged‑in user take over other users’ non‑personal teams, giving them full access to all associated data. The issue was fixed in version 5.9.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
kreaweb Genealogy, versions earlier than 5.9.1, used by organizations managing family‑tree data.
Real-world impact
An attacker who is already logged in could hijack any other user’s team, gaining unrestricted read and write access to all genealogy records in that team.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is exploitable over the network, requires only low privilege, and gives attackers complete control over data, making it a critical risk.
What to do about it
- 01Upgrade Genealogy to version 5.9.1 or later.
NVD-referenced vendor advisory
Timeline
- Apr 7, 2026 · Apr 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/MGeurts/genealogy/security/…exploitvendor advisory