Authorization Bypass in Roskus Prospero Flow CRM Allows Unrestricted Ticket Access
CVE-2026-19539
8.6HIGH
What is CVE-2026-19539?
The ticket management component in Roskus Prospero Flow CRM prior to version 5.4.9 suffers from an authorization bypass vulnerability. This issue permits authenticated users from any company to access full ticket content of other companies, including sensitive data such as titles, descriptions, and attachments. Additionally, users can hijack tickets belonging to other companies by manipulating the company_id or can delete these tickets without adequate authorization checks. The exploitation occurs due to query operations that fail to restrict data access based on the user's company constraints, compounded by the delete operation's inadequate permission enforcement.
Affected Version(s)
Prospero Flow CRM 0 < 5.4.9
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
DarĂo Rivas Quero
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Gustavo Novaro
