Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitHub adds 3-day Dependabot cooldown to block malicious package updates
July 27, 2026
NVIDIA Forms Open Secure AI Alliance for AI Agent Defenses
July 27, 2026
MedusaHVNC Malware Lets Attackers Remotely Control PCs
July 27, 2026
Home/Threats/Vatican Click to Pray App API Flaw Exposes 700,000 User Records
Threats

Vatican Click to Pray App API Flaw Exposes 700,000 User Records

Key Takeaways An unauthenticated API vulnerability in the Vatican’s “Click to Pray” app exposed the personal data of over 700,000 users. The flaw, an Insecure Direct Object...

Jennifer sherman
Jennifer sherman
July 27, 2026 3 Min Read
3 0

Key Takeaways

  • An unauthenticated API vulnerability in the Vatican’s “Click to Pray” app exposed the personal data of over 700,000 users.
  • The flaw, an Insecure Direct Object Reference (IDOR), allowed unauthorized access to names, email addresses, country, and user roles.
  • The vulnerability was discovered by ethical hacker BobDaHacker in January and remained unpatched at the time of reporting.
  • Exposed data could facilitate highly convincing phishing and social engineering attacks targeting users of the papal prayer network.
  • This incident underscores the critical importance of robust access control mechanisms and API authorization testing for organizations handling personal data.

The Vatican’s official “Click to Pray” application, designed to connect users with daily prayers and papal content, has inadvertently exposed the personal information of over 700,000 individuals. This significant data leak stems from a critical flaw in the app’s API, which permitted unauthorized access to user records without requiring any authentication.

Table Of Content

  • Key Takeaways
  • Unauthenticated API Exposes User Records
  • The IDOR Flaw Explained
  • Implications of the Exposure
  • Phishing Risks and Security Lessons
  • Threats Posed by Exposed Data

The vulnerability allowed anyone with a standard web browser to retrieve sensitive account data simply by manipulating user IDs, bypassing login procedures entirely. This security lapse affected users who had provided their names, email addresses, passwords, and in some cases, their country of origin when registering for the service.

Unauthenticated API Exposes User Records

The IDOR Flaw Explained

The exposure was identified by ethical hacker BobDaHacker, who uncovered an Insecure Direct Object Reference (IDOR) vulnerability in January. This type of flaw occurs when an application exposes a direct reference to an internal implementation object, such as a user ID, and fails to verify if the requesting user is authorized to access that specific object.

In the case of the “Click to Pray” app, the vulnerable API assigned sequential user IDs to each account. By merely incrementing these IDs in a web request, an unauthenticated individual could systematically access and view the associated account details for a vast number of users. DarkReading, which independently verified the issue, noted that the vulnerability was still accessible at the time of their publication, detailed in a technical report.

The exposed data included users’ full names, email addresses, country information, account deletion status, and assigned user roles (e.g., “PRAYER” for ordinary users, or staff-associated roles for lower-numbered accounts). This readily accessible data trove, which required no advanced technical expertise to extract, could be exploited by malicious actors.

Implications of the Exposure

As a DarkReading said in a report, this incident is not a malware attack but rather an access-control failure with potentially severe consequences. The ease with which this data could be harvested, simply through browser requests, significantly lowers the bar for criminals to craft sophisticated phishing campaigns and social engineering lures. The sequential nature of the user IDs made bulk data collection particularly straightforward.

Phishing Risks and Security Lessons

Threats Posed by Exposed Data

The availability of users’ names and email addresses allows attackers to create highly credible fraudulent emails. These could reference faith, prayer requests, donation appeals, or other Vatican-related content, making the messages appear legitimate. Victims are far more likely to open and interact with emails that are personalized with their actual account details, increasing the efficacy of such scams. Similar risks were observed in the NVIDIA personal data breach, where exposed identifiers also supported targeted phishing and credential attacks.

This incident serves as a stark reminder that robust access control is fundamental to web security. The <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/110b51be-5abb-4737-a65e-5acfd85eccc2/Vaticans-Click-to-Pray-App-Exposes-700000-Users-Through-Unauthenticated-API-Flaw.pdf?AWSAccessKeyId=ASIA2F3EMEYESJDZ4OVZ&Signature=bGShBgdK%2FfF9mvolzt4yGYK%2BElI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIX%2F%2F%2F%2

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwarephishingSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Claude Opus 5 AI Identifies Software Vulnerabilities, Cannot Create Exploits

Next Post

MedusaHVNC Malware Lets Attackers Remotely Control PCs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Disable Industrial Safety Alarms in Critical Infrastructure
July 27, 2026
Wrench Attacks Force Crypto Wallet Unlocks, Bypassing Encryption
July 27, 2026
Critical iOS Vulnerability Exposes User Data to Tracking via 84 Hidden Streams
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us