Roskus · Prospero Flow Crm · CVE-2026-59233
**Name of the Vulnerable Software and Affected Versions**
Roskus Prospero Flow CRM versions prior to 5.2.1
**Description**
The permission management component contains a flaw where the permission save endpoint does not perform authorization checks. This allows any authenticated user to grant any role, including their own, the full set of application permissions by sending a crafted POST request to the endpoint, which then synchronizes the submitted permissions to the specified role.
**Recommendations**
Update to version 5.2.1 or later.