www.darkreading.com 7/24/2026, 1:20:26 PM · external

Vatican prayer app leaks 700k users’ data via insecure API

Vatican prayer app leaks 700k users’ data via insecure API
CyberSIXT Evidence Panel
Primary Source bobdahacker.com

THE Vatican's official prayer app, Click to Pray, has exposed the personal identifiable information (PII) of over 700,000 users due to an insecure API vulnerability. Discovered by a white-hat hacker, the vulnerability allows unauthorized access to users' names, email addresses, locations, and account statuses. Despite attempts to alert the Pope's Worldwide Prayer Network about the leak, no immediate action was taken to secure the system.

Experts highlight IDOR (Insecure Direct Object References) as a prevalent security issue in web applications, emphasizing the need for organizations to address basic cybersecurity vulnerabilities. Users can protect themselves by providing anonymized information during registration, and institutions handling sensitive data must enhance their security protocols, regardless of their industry.

View Primary Source Via www.darkreading.com

Article by CyberSIXT