Authorization Bypass Vulnerability in Roskus Prospero Flow CRM
CVE-2026-77780
5.3MEDIUM
What is CVE-2026-77780?
An authorization bypass vulnerability exists in Roskus Prospero Flow CRM that allows users with transaction and accounting creation permissions to access sensitive information from other companies. Specifically, it permits the disclosure of a company's bank account name, bank name, and the last four digits of the bank card. This occurs through inadequate ownership checks in the POST request to the /transaction/save endpoint, enabling user-controlled keys to bypass necessary authorization protocols.
Affected Version(s)
Prospero Flow CRM 4.9.1 < 5.14.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adrián GarcĂa LĂłpez
Xoán M. Otero Jorge
DarĂo Rivas Quero
Secur0 CNA
Gustavo Novaro
