Insecure Direct Object Reference in Prospero Flow CRM by Roskus
CVE-2026-59240

6.9MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
27 July 2026

What is CVE-2026-59240?

The vulnerability in Prospero Flow CRM arises from an Insecure Direct Object Reference (IDOR) in the DeleteNotificationController::delete() method. This flaw allows any authenticated user to delete notifications belonging to any other user without proper access checks. Specifically, the system fails to validate user or company ownership when deleting notifications. Attackers can exploit sequential notification identifiers to systematically remove notifications, thus denying affected users access to important alerts and notifications.

Affected Version(s)

Prospero Flow CRM 1.0.0 < 5.5.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Rivas Quero
Cristian Fernandez Cornejo
Xoan M. Otero Jorge
Gustavo Novaro
Secur0 CNA
.