< Back to all clusters
[TECHNOLOGY] · Vatican City · 2 sources

Vatican Prayer App Exposes 719,000 Users' Personal Data

Security researchers discovered a critical IDOR flaw in the Vatican's official "Click to Pray" application, which serves the Pope’s Worldwide Prayer Network. The vulnerability allowed anyone to retrieve full personal records—email, name, birthdate, country and role—by incrementing a numeric user ID, exposing data from roughly 719,000 accounts.

The flaw was reported in early January 2026 by the researcher known as BobDaHacker, but the Vatican did not respond. The issue became public in July after a journalist inquiry, and a fix was applied without notifying the discoverer. A second weakness was also found: the registration endpoint returned the validation hash used for email verification, permitting account creation without access to the email inbox. Additionally, confirmation emails failed basic SPF/DKIM/DMARC checks, increasing phishing risk.

Entities: BobDaHacker · Click to Pray · Pope Francis · Pope’s Worldwide Prayer Network · Vatican City

Sources

about 7 hours ago