PT-2026-69848 · Roskus · Prospero Flow Crm

·

CVE-2026-19433

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.4.8
Description An authorization bypass exists in the contact management component. Authenticated users can overwrite contact data belonging to other companies or download personal data as a vCard by manipulating the contact's numeric identifier. This occurs because the save and export operations retrieve records without restricting the query to the company associated with the authenticated user.
Recommendations Update Roskus Prospero Flow CRM to version 5.4.8 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19433

Affected Products

Prospero Flow Crm