Description
A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The description indicates that Eleveo Call Recording Software 9.7.0 contains a flaw in the /callrec/statisticReportAction.do endpoint that allows remote actors to manipulate requests and bypass authentication checks. This improper authorization is characterized by CWE-266 and CWE-285, enabling attackers to access data or functions that should be restricted. The vulnerability can be exploited remotely without local or privileged execution on the target system.

Affected Systems

The affected product is Eleveo Call Recording Software version 9.7.0. The vulnerability resides specifically in the statisticReportAction.do function of the /callrec package and does not appear to affect other versions or components based on the available information.

Risk and Exploitability

With a CVSS score of 5.3, the risk is classified as medium severity. An EPSS score of < 1% indicates a very low probability of exploitation, but the publicly disclosed exploit demonstrates that the vulnerability can be used in practice. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack means that the exposed endpoint remains reachable for malicious actors until a patch or mitigation is applied. This limited exploitation likelihood does not negate the potential for unauthorized data access, confidentiality violations, or integrity tampering if the endpoint is reached by an attacker.

Generated by OpenCVE AI on July 29, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Eleveo to request a patch or a temporary fix, and if no update is forthcoming, work with the vendor to implement a temporary workaround.
  • Restrict access to the /callrec/statisticReportAction.do endpoint using firewall or router ACLs so that only trusted users and networks can reach it.
  • Enable detailed logging for all requests to statisticReportAction.do and actively monitor those logs for anomalous or unauthorized activity, generating alerts when suspicious patterns are detected.

Generated by OpenCVE AI on July 29, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 18:00:00 +0000


Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software statisticReportAction.do improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T17:21:17.573Z

Reserved: 2026-07-10T08:47:17.326Z

Link: CVE-2026-15376

cve-icon Vulnrichment

Updated: 2026-07-10T20:26:41.953Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:45:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization