Vatican’s ‘Click to Pray’ App Exposes 700,000 Users’ Data

The Vatican’s official prayer application, ‘Click to Pray,’ has been found to expose the personal information of over 700,000 users due to a significant security flaw. This vulnerability, present for at least six months, allowed unauthorized access to user data through the app’s API without requiring authentication.

‘Click to Pray’ is a platform that offers daily prayers and papal content, accessible via its website and mobile applications. Users typically provide personal details such as names, email addresses, and, in some cases, their country of residence when creating accounts. This information was intended to be securely stored and protected.

The security issue was identified by a researcher known as ‘BobDaHacker’ in January 2026. The flaw involved an insecure direct object reference (IDOR) vulnerability, where the app assigned sequential user IDs to each account. By manipulating these IDs, an unauthenticated individual could access the personal information associated with any account. This exposed data included users’ first and last names, email addresses, country identifiers, account deletion status, and assigned roles.

Despite multiple attempts to alert the app’s developers, there was no response or corrective action for six months. The issue only gained attention and was addressed after public disclosure by security journalist Nate Neslon. Prior to this, neither the researcher nor the journalist received acknowledgment from the app’s creators.

This incident underscores the critical importance of robust cybersecurity practices, even in applications that may seem innocuous, such as prayer apps. Organizations handling personal data must ensure that every API request includes proper identity verification and permission checks to prevent unauthorized access. Users are advised to be cautious when sharing personal information online and to monitor their accounts for any suspicious activity.

In light of this breach, it is imperative for organizations to prioritize security measures, including regular audits and prompt responses to identified vulnerabilities. This proactive approach is essential to protect user data and maintain trust in digital platforms.