CVE-2026-19734

8.6

Roskus · Prospero Flow CRM

An authorization bypass vulnerability in the Prospero Flow CRM product management component allows authenticated users to access or modify data belonging to other tenants.

Executive summary

Prospero Flow CRM is vulnerable to an authorization bypass that could lead to cross-tenant data exposure and unauthorized modification of product information.

Vulnerability

This is an authorization bypass (CWE-639) occurring in the product management module. The vulnerability requires the attacker to be authenticated, but it allows them to manipulate user-controlled keys to access resources outside of their authorized scope.

Business impact

Successful exploitation results in unauthorized access to sensitive product data across different tenants. This could lead to a significant breach of data privacy, loss of competitive intelligence, and unauthorized modification of business-critical information. The CVSS score of 8.6 reflects the high impact on data confidentiality and integrity within the CRM environment.

Remediation

Immediate Action: Upgrade to version 5.4.7 or higher immediately to resolve the authorization logic flaw.

Proactive Monitoring: Audit access logs for anomalous patterns, specifically looking for users attempting to access resource IDs that do not belong to their assigned tenant.

Compensating Controls: Enforce strict session management and, if possible, implement application-level authorization checks that validate the ownership of resources before processing requests.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk of cross-tenant data leakage is severe for a CRM platform. Administrators must apply the vendor-provided update to version 5.4.7 as soon as possible to ensure that tenant isolation is properly enforced.

More Roskus CVEs