Authorization Bypass in Roskus Prospero Flow CRM
CVE-2026-59236
6.9MEDIUM
What is CVE-2026-59236?
An authorization bypass vulnerability exists in Roskus Prospero Flow CRM's Excel import handlers which allows a remote, authenticated user to create records in another company's tenant. This is due to the system's failure to verify that the company_id in the uploaded spreadsheet matches the authenticated user's company. As a result, attackers may exploit this vulnerability by manipulating the company_id column in the input file to gain unauthorized access to sensitive data and create records across tenants.
Affected Version(s)
Prospero Flow CRM 1.0.0 < 5.14.0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mario Ălvarez FernĂĄndez (maalfer)
Thomas O'Neil Ălvarez (thomas.pime)
Gustavo Novaro
Xoan M. Otero Jorge
Cristian FernĂĄndez Cornejo
Secur0 CNA
