Authorization Bypass Vulnerability in Roskus Prospero Flow CRM
CVE-2026-19870
8.6HIGH
What is CVE-2026-19870?
An authorization bypass vulnerability exists in the payroll module of Roskus Prospero Flow CRM prior to version 5.15.10. This vulnerability allows authenticated users with read payroll permissions to access the salary and banking information of employees across different companies within the CRM instance. Furthermore, users with create payroll permissions can generate payroll records for employees not affiliated with their own company. This issue arises due to a listing query that fails to limit data access to the calling user's company context, while the employee identifier is validated for global existence rather than confined to a specific company.
Affected Version(s)
Prospero Flow CRM 0 < 5.15.10
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Manuel MartĂnez Casasola
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Gustavo Novaro
