Authorization Bypass in Roskus Prospero Flow CRM
CVE-2026-59236

6.9MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
15 July 2026

What is CVE-2026-59236?

An authorization bypass vulnerability exists in Roskus Prospero Flow CRM's Excel import handlers which allows a remote, authenticated user to create records in another company's tenant. This is due to the system's failure to verify that the company_id in the uploaded spreadsheet matches the authenticated user's company. As a result, attackers may exploit this vulnerability by manipulating the company_id column in the input file to gain unauthorized access to sensitive data and create records across tenants.

Affected Version(s)

Prospero Flow CRM 1.0.0 < 5.14.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mario Álvarez Fernåndez (maalfer)
Thomas O'Neil Álvarez (thomas.pime)
Gustavo Novaro
Xoan M. Otero Jorge
Cristian FernĂĄndez Cornejo
Secur0 CNA
.