PT-2026-60108 · Roskus+1 · Prospero Flow Crm

·

CVE-2026-59236

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.14.0
Description An authorization bypass exists in the Excel import handlers (CustomerImport, LeadImport, and ProductImport). A remote, authenticated user can create customer, lead, and product records within another company's tenant by uploading a spreadsheet to the POST '/customer/import/excel/save' endpoint. The system maps the company id variable directly from the uploaded file without verifying if it matches the authenticated user's company, allowing the company id to be controlled by the user.
Recommendations Update Roskus Prospero Flow CRM to version 5.14.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59236

Affected Products

Prospero Flow Crm