Description
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the /callrec/sendlogfile endpoint of Eleveo Call Recording Software 9.7.0. An attacker can manipulate requests to this functionality, bypassing the authorization checks that normally protect the endpoint. This improper authorization can allow the attacker to interact with the endpoint in unauthorized ways, as the check is not properly enforced.

Affected Systems

Any deployment of Eleveo Call Recording Software version 9.7.0 that includes the callrec component is affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the vulnerability can be triggered remotely, increasing its potential impact on exposed systems. The EPSS score of < 1% suggests a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Nonetheless, the public disclosure of the exploit means that threat actors could attempt to abuse the unauthorized access if the endpoint remains reachable from untrusted networks.

Generated by OpenCVE AI on July 31, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch for Eleveo Call Recording Software 9.7.0 once it becomes available.
  • Restrict network access to the /callrec/sendlogfile endpoint using firewall rules or network segmentation so that only trusted internal systems can reach it.
  • If the sendlogfile functionality is not required for your deployment, disable or block the endpoint entirely and monitor server logs for unauthorized access attempts.

Generated by OpenCVE AI on July 31, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 18:00:00 +0000


Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software sendlogfile improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T17:24:35.682Z

Reserved: 2026-07-10T08:47:20.246Z

Link: CVE-2026-15377

cve-icon Vulnrichment

Updated: 2026-07-10T16:44:17.883Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T17:16:54.430

Modified: 2026-07-13T18:16:27.740

Link: CVE-2026-15377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization