Authorization Bypass Vulnerability in Roskus Prospero Flow CRM
CVE-2026-19870

8.6HIGH

Key Information:

Vendor

Roskus

Vendor
CVE Published:
14 August 2026

What is CVE-2026-19870?

An authorization bypass vulnerability exists in the payroll module of Roskus Prospero Flow CRM prior to version 5.15.10. This vulnerability allows authenticated users with read payroll permissions to access the salary and banking information of employees across different companies within the CRM instance. Furthermore, users with create payroll permissions can generate payroll records for employees not affiliated with their own company. This issue arises due to a listing query that fails to limit data access to the calling user's company context, while the employee identifier is validated for global existence rather than confined to a specific company.

Affected Version(s)

Prospero Flow CRM 0 < 5.15.10

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel MartĂ­nez Casasola
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Gustavo Novaro
.