CVE-2026-19433

8.6

Roskus · Prospero Flow CRM

Roskus Prospero Flow CRM contains an authorization bypass vulnerability in its contact management component, allowing authenticated users to access or modify data via user-controlled keys.

Executive summary

An authorization bypass vulnerability in the Roskus Prospero Flow CRM contact management component exposes sensitive data to authenticated attackers, requiring an urgent update.

Vulnerability

This vulnerability is classified as CWE-639, representing an Insecure Direct Object Reference (IDOR) or authorization bypass. It allows an authenticated attacker to manipulate user-controlled keys to access records they are not authorized to view or modify.

Business impact

The ability to bypass authorization checks in a CRM system directly threatens the confidentiality and integrity of customer records. A CVSS score of 8.6 indicates that this is a critical risk, potentially leading to unauthorized data exports or modifications that could result in severe reputational damage and regulatory non-compliance.

Remediation

Immediate Action: Upgrade to version 5.4.8 or higher to resolve the authorization logic flaw.

Proactive Monitoring: Review audit logs for suspicious export activity or access patterns where users are requesting records outside of their standard operational scope.

Compensating Controls: Deploy a Web Application Firewall (WAF) to detect and block requests that exhibit signs of parameter tampering or ID-based enumeration.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk to data privacy. Organizations should immediately update their Prospero Flow CRM instances to the patched version to prevent unauthorized access to sensitive contact information.

More Roskus CVEs