Description
A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in Eleveo Call Recording Software 9.7.0 that allows a remote attacker to manipulate the /callrec/roleAddAction.do endpoint. This leads to improper authorization, enabling unauthorized users to gain access to the Group Interface. The vulnerability originates from an unknown function within that component, and the exploit is publicly available.

Affected Systems

The software vendor Eleveo produces the Call Recording Software, specifically version 9.7.0. Systems running this version are directly affected; no other versions were listed in the provided CVE data.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the moderate range, yet the attack vector is remote and the exploit has already been published, indicating that attackers can launch the attack without needing local privileges. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog. The risk remains significant because the flaw directly impacts authorization controls and could allow unauthorized actions within the application.

Generated by OpenCVE AI on July 29, 2026 at 10:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install any vendor‑supplied patch or update for Eleveo Call Recording Software that addresses the Group Interface authorization flaw.
  • If a patch is not yet available, restrict network access to the /callrec/roleAddAction.do endpoint to trusted administrators only, ensuring that only users with legitimate role‑management permissions can reach it.
  • Review and enforce the principle of least privilege for all accounts that interact with the software, disabling or removing any unnecessary service roles that could be abused through the vulnerable endpoint.

Generated by OpenCVE AI on July 29, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Eleveo call Recording
Vendors & Products Eleveo call Recording

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software Group roleAddAction.do improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T14:34:14.669Z

Reserved: 2026-07-10T08:47:10.996Z

Link: CVE-2026-15374

cve-icon Vulnrichment

Updated: 2026-07-10T15:47:50.882Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:00:13Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization