PT-2026-79384 · Roskus · Prospero Flow Crm

·

CVE-2026-77780

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions 4.9.1 through 5.14.0
Description An authorization bypass exists in the transaction save endpoint. A user with transaction and accounting creation permissions can disclose sensitive banking information from another company, including the bank account name, bank name, and the last four digits of a card. This occurs when a bank account id or bank card id belonging to another company is provided in the POST '/transaction/save' endpoint, as the system persists and renders the data without verifying company ownership.
Recommendations Update Roskus Prospero Flow CRM to a version later than 5.14.0. As a temporary mitigation, restrict user permissions for transaction and accounting creation to trusted personnel only.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77780

Affected Products

Prospero Flow Crm