Access Control Weakness in Eleveo Call Recording Software by Eleveo
CVE-2026-101144
Key Information:
- Vendor
Eleveo
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-101144?
The Eleveo Call Recording Software version 9.7.0 contains a vulnerability within its Query Builder component, specifically affecting the /callrec/searchAction.do file. This vulnerability enables an attacker to bypass access controls, potentially allowing unauthorized remote access to sensitive functionalities. The issue has been publicly disclosed, raising concerns about its exploitation. Despite early notifications to the vendor regarding this flaw, there has been no response or remediation action taken.
Affected Version(s)
Call Recording Software 9.7.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
