Insecure Direct Object Reference in Prospero Flow CRM by Roskus
CVE-2026-59240
6.9MEDIUM
What is CVE-2026-59240?
The vulnerability in Prospero Flow CRM arises from an Insecure Direct Object Reference (IDOR) in the DeleteNotificationController::delete() method. This flaw allows any authenticated user to delete notifications belonging to any other user without proper access checks. Specifically, the system fails to validate user or company ownership when deleting notifications. Attackers can exploit sequential notification identifiers to systematically remove notifications, thus denying affected users access to important alerts and notifications.
Affected Version(s)
Prospero Flow CRM 1.0.0 < 5.5.1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dario Rivas Quero
Cristian Fernandez Cornejo
Xoan M. Otero Jorge
Gustavo Novaro
Secur0 CNA
