Prayer App Leak - Another Vatican Cybersecurity Incident
The 'Click to Pray' app, which is connected to the Vatican, exposed user information for months due to a security vulnerability, reports the unknown cybersecurity publication Dark Reading.
The app, which is available on iOS and Android, is operated by the Pope's Worldwide Prayer Network, a pontifical society entrusted to the Jesuits.
Dark Reading reports that the app contained an Insecure Direct Object Reference (IDOR) vulnerability. This occurs when an application allows users to request information using an account or record number, but fails to verify that they are authorised to view it.
By altering these identifiers, an attacker can access other users' data because proper security checks are absent.
Names and email addresses linked to over 700,000 accounts were accessible through this flaw.
The vulnerability was reportedly discovered in January 2026 by an independent security researcher known as 'BobDaHacker'. He claimed that repeated attempts to notify the relevant parties went unanswered before the issue was made public.
This incident is the latest in a series of cybersecurity issues demonstrating the unreliability of the Vatican's digital infrastructure.
Vatican websites have experienced outages several times over the last 20 years. In 2023, confidential documents from the Vatican's Synod on Synodality were reportedly found on an unsecured cloud server.
#newsTvewmkshuv
