Authorization Bypass Vulnerability in Roskus Prospero Flow CRM
CVE-2026-77780

5.3MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
21 August 2026

What is CVE-2026-77780?

An authorization bypass vulnerability exists in Roskus Prospero Flow CRM that allows users with transaction and accounting creation permissions to access sensitive information from other companies. Specifically, it permits the disclosure of a company's bank account name, bank name, and the last four digits of the bank card. This occurs through inadequate ownership checks in the POST request to the /transaction/save endpoint, enabling user-controlled keys to bypass necessary authorization protocols.

Affected Version(s)

Prospero Flow CRM 4.9.1 < 5.14.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrián García López
Xoán M. Otero Jorge
DarĂ­o Rivas Quero
Secur0 CNA
Gustavo Novaro
.