Information Disclosure in ITFlow IT Documentation and Ticketing System
CVE-2026-47755

6.5MEDIUM

Key Information:

Vendor

Itflow-org

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-47755?

ITFlow's IT documentation and ticketing system exposes a serious security flaw that allows low-privileged authenticated users to access plaintext credentials and TOTP secrets of other clients. This vulnerability arises as the system does not adequately enforce client scoping or object-level authorization, permitting unauthorized access through direct requests to the credential edit modal using arbitrary credential IDs. The issue has been addressed in version 26.05, which enforces proper access controls to secure user credentials.

Affected Version(s)

itflow < 26.05

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.