CIVI-SA-2026-36: Information disclosure in APIv4

If a user has access to APIv4 REST for purposes of creating/updating one kind of record (such as Contribution), then they may be able to infer implicit information from a related record-type (such as Contact), even if the user lacks regular access to the Contact.

This vulnerability arises from insufficient security checks in the "write/join" mechanism.

Security Risk
Moderately Critical
Vulnerability
Information Disclosure
Affected Versions

CiviCRM v6.16.3 and earlier

Fixed Versions

CiviCRM v6.17.0, v6.16.4, v6.10.9 (ESR), and later

Publication Date
Solutions

Any ONE of the following will mitigate the vulnerability:

  • Upgrade to a fixed version of CiviCRM, or...
  • Apply the following patch
Credits

Coleman Watts of CiviCRM Core Team, Jakub Fidler