CVE-2026-19870

8.6

Roskus · Prospero Flow CRM

Prospero Flow CRM contains an authorization bypass vulnerability in the payroll module, allowing low-privileged users to access or create cross-tenant payroll data.

Executive summary

Roskus Prospero Flow CRM versions prior to 5.15.10 are affected by an authorization bypass vulnerability that permits unauthorized access to sensitive payroll information.

Vulnerability

This vulnerability (CWE-639) involves an authorization bypass through a user-controlled key within the payroll module. An attacker with low-level user privileges can manipulate this key to access or modify data belonging to other tenants.

Business impact

This flaw leads to severe data privacy violations, as it allows cross-tenant access to sensitive financial and payroll records. The potential for unauthorized disclosure or manipulation of payroll data presents significant reputational and legal risks to organizations. The CVSS score of 8.6 reflects the high impact on data confidentiality and integrity.

Remediation

Immediate Action: Upgrade Prospero Flow CRM to version 5.15.10 or higher immediately.

Proactive Monitoring: Audit access logs for the payroll module to identify any unauthorized attempts by users to access records outside of their assigned tenant scope.

Compensating Controls: Implement strict access control lists and review user permissions to ensure that the principle of least privilege is enforced across all CRM modules.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations using Prospero Flow CRM must treat this as a high-priority update. Because this vulnerability allows for cross-tenant data exposure, the risk of data leakage is substantial, and patching should be performed during the next maintenance window.

More Roskus CVEs