CVE-2026-59233
8.7Roskus · Prospero Flow CRM
Roskus Prospero Flow CRM contains an authorization bypass vulnerability in its permission management component, allowing authenticated users to perform unauthorized actions.
Executive summary
An authorization bypass vulnerability in Roskus Prospero Flow CRM allows authenticated users to escalate privileges and access restricted management functions.
Vulnerability
The application suffers from missing authorization checks in the permission management component. An authenticated user can bypass intended security controls by manipulating user-controlled keys, effectively granting them unauthorized access to sensitive endpoints.
Business impact
The CVSS score of 8.7 reflects the high risk of this vulnerability. Successful exploitation could lead to unauthorized administrative actions, data manipulation, or exposure of sensitive CRM data, significantly impacting the confidentiality and integrity of the business operations.
Remediation
Immediate Action: Upgrade to Prospero Flow CRM version 5.2.1 or higher immediately to apply the necessary authorization checks.
Proactive Monitoring: Monitor audit logs for unauthorized access attempts to the permission management endpoints or changes to user role configurations.
Compensating Controls: Restrict access to the CRM to known IP ranges and ensure that administrative interfaces are not exposed to the public internet.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations relying on Prospero Flow CRM must treat this as a high-priority update. Ensure the software is patched to version 5.2.1 to prevent unauthorized access to sensitive management functions.