PT-2026-70206 · Roskus · Prospero Flow Crm

·

CVE-2026-19539

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.4.9
Description An authorization bypass exists in the ticket management component. Authenticated users can access, modify, or delete tickets belonging to other companies using the ticket's numeric identifier. This occurs because read and save operations do not restrict queries to the authenticated user's company. Additionally, the delete controller uses a generic IlluminateHttpRequest instead of the TicketDeleteRequest, which fails to enforce necessary permissions. This allows users to read full ticket content (title, description, and attachments), hijack tickets by reassigning the company id variable, or delete tickets without authorization.
Recommendations Update Roskus Prospero Flow CRM to version 5.4.9 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19539

Affected Products

Prospero Flow Crm