There has been a security release for CiviCRM. Upgrades are available for:
- CiviCRM v6.17.2 (download, 6.17.0 release notes, 6.17.1 release notes)
- CiviCRM v6.16.5 (download, 6.16.4 release notes, 6.16.5 release notes)
- CiviCRM v6.10 ESR (info, download, release notes)
These upgrades address the following security issues:
- CIVI-SA-2026-35: Permission Bypass in APIv4 - Highly Critical (read the advisory for a hotfix if you cannot upgrade)
- CIVI-SA-2026-36: Information disclosure in APIv4 - Moderately Critical
- CIVI-SA-2026-37: Additional Permission Bypass in APIv4
Learn more about subscribing to Extended Security Releases (ESR).
Notes
1. After the initial release of 6.16.4 / 6.17.0 There was a subsequent secuirty issue which prompted CIVI-SA-2026-37 to be issued and 6.16.5 / 6.17.1 to be released. There was an issue with a status check in those releases and 6.16.5 was re-released but the fix for the status check was put into 6.17.2
Support CiviCRM
We are committed to keeping CiviCRM free and open, forever. We depend on your support to help make that happen.
- Make a donation or contribute to a Make it happen campaign.
- If your organization wants to support our work, please become a member today.
- If you are a CiviCRM service provider, please become a partner.
CiviCRM is community driven and is sustained through contributions, good vibes, solidarity, and financial support from its community. Help CiviCRM do a world of good.
