PT-2026-72014 · Roskus · Prospero Flow Crm

·

CVE-2026-19870

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.15.10
Description An authorization bypass exists in the payroll module where the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership. This allows authenticated users with read payroll permissions to view salary and banking details of employees from any other company within the instance. Additionally, users with create payroll permissions can create payroll records attributed to employees of other companies.
Recommendations Update Roskus Prospero Flow CRM to version 5.15.10 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19870

Affected Products

Prospero Flow Crm