HomeCyber BalkansAnyone with a Browser Can Access 700,000 Vatican Prayer App Accounts

Anyone with a Browser Can Access 700,000 Vatican Prayer App Accounts

Published on

spot_img

A significant security breach has recently been uncovered involving the Vatican’s “Click to Pray” platform, a digital service linked to the Pope’s Worldwide Prayer Network. This vulnerability, which pertains to access control, has compromised the personal data of over 700,000 users, underscoring a continuing trend where basic web security misconfigurations expose large user bases to potential risks.

The “Click to Pray” service is designed to deliver daily prayers and Vatican-related content to a global audience through various platforms, including web, iOS, and Android. Its widespread usage creates a particular concern when vulnerabilities are found, as they can affect a substantial number of individuals.

Central to this issue is a type of vulnerability known as insecure direct object reference (IDOR), which is recognized as one of the most common forms of broken access control. This particular flaw allows unauthenticated users to access and enumerate user accounts easily by querying an exposed API endpoint. By simply iterating through sequential user IDs, malicious actors can access sensitive account records without needing any valid authentication or authorization credentials. This effectively turns what should be a secure application into an open directory of user data, a situation that is both alarming and preventable.

According to technical validations conducted by cybersecurity expert Dark Reading, the dissected exposed endpoint made it possible to retrieve personally identifiable information (PII) such as full names, email addresses, and country identifiers, all in numeric format. Moreover, the data set revealed critical internal metadata, including account statuses—active or deleted—and user privilege levels, differentiating standard users from administrative or staff accounts. Notably, lower user ID values had been associated with organizational staff, thereby heightening the risk for targeted attacks against these individuals.

The vulnerability’s ease of exploitation is particularly concerning, as it requires little more than a simple browser request to a predictable API structure. The lack of complexity in exploiting this vulnerability significantly reduces the barriers for malicious entities, facilitating mass data harvesting through straightforward scripting techniques.

Despite attempts at responsible disclosure by the independent researcher BobDaHacker, who identified the vulnerability earlier this year, no patch was available at the time of reporting, casting doubt on the maturity of the vulnerability response mechanisms in place within this ecosystem. Efforts to inform both the Pope’s Worldwide Prayer Network and the development firm, La Machi, remained unfruitful, further amplifying worries about the overall effectiveness of security protocols in such important applications.

From a cybersecurity perspective, the ramifications of this exposed dataset are considerable. The potential for targeted phishing campaigns becomes significantly more pronounced, particularly ones that could exploit users’ trust in a religious institution. Attackers could easily impersonate official Vatican communications, distributing malicious links or pages designed to capture user credentials at scale. Historical data indicates that similar incidents involving leaked datasets have given rise to extensive social engineering campaigns that leverage compromised user information effectively.

This incident also highlights a more extensive problem within the technology industry. IDOR vulnerabilities consistently rank among the OWASP Top Ten categories of broken access control, a critical web application risk that has persisted since 2021. While modern frameworks generally enforce user authentication, they often leave authorization logic to the developers, leading to security gaps where sensitive information is inadequately protected. In this situation, although the application executed checks to determine if a user was logged in, it failed to ensure that the logged-in user had authorization to access specific records, a subtle but crucial oversight that continues to lead to widespread security incidents across various sectors.

Interestingly, some users might have inadvertently mitigated their exposure. Reports from Dark Reading suggest that individuals who registered with anonymized information, such as Apple’s “Hide My Email” feature or pseudonymous identifiers, were able to protect their true identities despite the data leak. This observation aligns with broader privacy best practices, which recommend minimizing the use of actual PII in applications that are not essential.

The incident also connects with a larger narrative on API security failures, an increasingly attractive target for attackers amid the rising reliance on microservices and mobile backends. Recent coverage regarding endpoint security risks, as well as ransomware attacks exploiting zero-day vulnerabilities, draws attention to how neglected API protections can serve as entry points for larger-scale cyber campaigns, further underlining the urgency for improved security measures in the digital landscape, particularly for significant organizations like the Vatican.

Source link

Latest articles

Cyber Briefing – 2026.07.27 – CyberMaterial

Cybersecurity Update: The Evolving Threat Landscape As the digital world continues to advance, recent reports...

Certighost Strikes Microsoft Active Directory Certificate Services

Microsoft Addressing a Critical Vulnerability in Active Directory Certificate Services In a significant development pertaining...

SourTrade Malvertising Campaign Covertly Installs Malware in Browsers

New Malvertising Techniques Unveiled by SourTrade Campaign, Experts Warn of Heightened Threats Operators behind the...

OpenAI Excluded from the New Open Secure AI Alliance

In a significant development within the tech industry, OpenAI has found itself conspicuously absent...

More like this

Cyber Briefing – 2026.07.27 – CyberMaterial

Cybersecurity Update: The Evolving Threat Landscape As the digital world continues to advance, recent reports...

Certighost Strikes Microsoft Active Directory Certificate Services

Microsoft Addressing a Critical Vulnerability in Active Directory Certificate Services In a significant development pertaining...

SourTrade Malvertising Campaign Covertly Installs Malware in Browsers

New Malvertising Techniques Unveiled by SourTrade Campaign, Experts Warn of Heightened Threats Operators behind the...