Description
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access / Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from improper access controls within the Query Builder component of Eleveo Call Recording Software. This flaw allows an attacker to manipulate requests to /callrec/searchAction.do and gain unauthorized access or elevate privileges, leading to potential data exposure or unauthorized configuration changes. The weakness is identified as a privilege escalation (CWE-266) and general improper access control (CWE-284).

Affected Systems

Eleveo Call Recording Software version 9.7.0 is affected by this issue. The vulnerability resides in the /callrec/searchAction.do file of the Query Builder component, which is deployed on systems running that specific version.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability. Exploitation is feasible over the network, as the web application component can be accessed remotely. Although EPSS information is not available and the vulnerability is not listed in CISA KEV, the public disclosure of exploit code suggests that attackers could potentially leverage this flaw to bypass authentication and gain unauthorized access. The lack of a vendor patch requires mitigations to be applied by system administrators.

Generated by OpenCVE AI on September 28, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch or update for Eleveo Call Recording Software that addresses the access control flaw.
  • Restrict access to the /callrec/searchAction.do endpoint to authenticated and authorized users only, for example by enforcing role‑based authentication or applying network firewall rules.
  • Configure the application to validate user permissions before executing the Query Builder features, ensuring that only privileged users can invoke searchAction.do, thereby preventing unauthorized privilege escalation.

Generated by OpenCVE AI on September 28, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software Query Builder searchAction.do access control
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T20:00:07.419Z

Reserved: 2026-09-28T08:11:27.828Z

Link: CVE-2026-101144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T21:17:12.153

Modified: 2026-09-28T21:17:12.153

Link: CVE-2026-101144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T21:30:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control