Description
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the /callrec/sendlogfile endpoint of Eleveo Call Recording Software 9.7.0, where an attacker can manipulate the request to bypass authorization checks and read or download log files that are normally protected. This flaw permits unauthorized access to logs that may contain sensitive call metadata, thereby compromising confidentiality.

Affected Systems

Any deployment of Eleveo Call Recording Software version 9.7.0 that includes the callrec component is affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the vulnerability can be triggered remotely, increasing its potential impact on exposed systems. The EPSS score of < 1% suggests a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Nonetheless, the public disclosure of the exploit means that threat actors could attempt to abuse the unauthorized access if the endpoint remains reachable from untrusted networks.

Generated by OpenCVE AI on July 26, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch for Eleveo Call Recording Software 9.7.0 once it becomes available.
  • Restrict network access to the /callrec/sendlogfile endpoint using firewall rules or network segmentation so that only trusted internal systems can reach it.
  • If the sendlogfile functionality is not required for your deployment, disable or block the endpoint entirely and monitor server logs for unauthorized access attempts.

Generated by OpenCVE AI on July 26, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 18:00:00 +0000


Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software sendlogfile improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T17:24:35.682Z

Reserved: 2026-07-10T08:47:20.246Z

Link: CVE-2026-15377

cve-icon Vulnrichment

Updated: 2026-07-10T16:44:17.883Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization