All incidents

Vatican prayer app exposes 700k users' data via insecure API

incidentopenJul 24, 2026 — Jul 28, 2026
Vatican prayer app exposes 700k users' data via insecure API

THE Vatican’s Click To Pray app leaked the personal data of over 700,000 users after an insecure API left names, email addresses and birth dates exposed for months. The issue was discovered by researcher BobDaHacker who reported the flaw in January 2026 and remained unaddressed until media coverage forced a fix.

The API flaw let anyone send a crafted request to retrieve a user’s profile, exposing names, email addresses, birth dates and even location information. A separate Insecure Direct Object Reference allowed attackers to validate or take over accounts by supplying email addresses they did not control. No CVE has been assigned to the vulnerability, but details were outlined in analysis by MalwareBytes covering the breach.

The vulnerability had been present since the app’s launch in 2019, requiring only simple HTTP requests to harvest data. Because the endpoint lacked any authentication or authorization checks, attackers could scrape records at scale without triggering alerts.

Despite several private reports to the Vatican’s prayer network beginning in January 2026, the flaw was left unpatched for over half a year. Only after coverage by security outlets such as Dark Reading highlighted the leak did the organization finally secure the endpoint. While no threat actors have been identified in the wild, the exposed data could be used for phishing or identity‑theft campaigns.

Organizations should audit all public APIs to ensure proper authorization tokens are required and that object references cannot be guessed or enumerated. Implementing rate limiting, using random identifiers and logging anomalous access patterns can help detect abuse early. For end users, limiting the amount of personal information shared during registration and using alias email addresses reduces the impact of any future exposure.

The Vatican has since locked down the API and urged users to update the Click To Pray app to the latest version. Security teams should treat this incident as a reminder to test third‑party services and apply patches promptly. Staying vigilant about basic flaws like IDOR remains the most effective way to prevent similar leaks.

Intelligence briefing updated Jul 28, 2026

Root sourcebobdahacker.com
Timeline Coverage

Swipe to explore timeline