
Securing APIs Against BOLA: The Click to Pray Leak
August 11, 2026 · allaboutcookies.org
A critical security flaw in the Vatican's Click to Pray application exposed the personal data of over 700,000 global users. This analysis highlights the technical details of the BOLA vulnerability, the registration hash leak, and practical steps to detect and prevent automated database harvesting.
Relevant FemtoSec Service
Proactively testing your systems, networks, applications, and infrastructure for vulnerabilities before attackers can find them. Our expert-led assessments simulate real-world threats to uncover weaknesses, ensure compliance, and strengthen your overall cybersecurity posture. Stay protected, stay ahead.






















