PT-2026-69482 · Roskus · Prospero Flow Crm

·

CVE-2026-59233

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.2.1
Description The permission management component contains a flaw where the permission save endpoint does not perform authorization checks. This allows any authenticated user to grant any role, including their own, the full set of application permissions by sending a crafted POST request to the endpoint, which then synchronizes the submitted permissions to the specified role.
Recommendations Update to version 5.2.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59233

Affected Products

Prospero Flow Crm