CVE-2026-77759

8.7

Roskus · Prospero Flow CRM

An authorization bypass vulnerability in the transaction API of Roskus Prospero Flow CRM allows unauthenticated users to access restricted data via user-controlled keys.

Executive summary

A critical authorization bypass in Roskus Prospero Flow CRM allows unauthenticated attackers to manipulate transaction data, posing a significant risk to data integrity.

Vulnerability

This vulnerability is a CWE-639 Authorization Bypass Through User-Controlled Key. The application fails to properly validate the identity of the requester when accessing the transaction API, allowing unauthenticated remote attackers to perform unauthorized actions.

Business impact

The ability for an unauthenticated user to interact with the transaction API could lead to unauthorized access to sensitive financial or business records. Given the CVSS score of 8.7, this flaw carries a high risk of data exposure and potential manipulation of business-critical workflows, which could result in severe reputational damage and regulatory non-compliance.

Remediation

Immediate Action: Upgrade to version 5.3.6 or later, or deploy version 5.5.3, which includes the necessary security fixes for this API flaw.

Proactive Monitoring: Monitor API access logs for anomalous request patterns targeting the transaction endpoints, specifically looking for unauthorized access attempts from unknown IP addresses.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to restrict access to the transaction API, ensuring that only trusted internal IP ranges can interact with these sensitive endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high CVSS severity and the nature of the authorization bypass require immediate attention. Administrators must prioritize patching the affected CRM instances to the recommended versions to prevent unauthorized data access and potential exploitation of the transaction API.

More Roskus CVEs