PT-2026-80862 · Roskus · Prospero Flow Crm

·

CVE-2026-78365

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions 4.0.0 through 5.3.1
Description An authorization bypass exists in the supplier API that allows an authenticated user to read, modify, and reassign supplier records belonging to other companies to their own. This is achieved by sending a PUT request to the '/api/supplier/{id}' endpoint and manipulating the company id variable within the request body.
Recommendations Update Roskus Prospero Flow CRM to a version later than 5.3.1. Restrict the use of the company id parameter in the '/api/supplier/{id}' endpoint to prevent unauthorized record reassignment.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78365

Affected Products

Prospero Flow Crm