Description
A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Eleveo Call Recording Software 9.7.0 contains a flaw in its pci_dss_status.jsp page that allows an attacker to bypass the built-in authorization checks. This improper handling of user credentials and permissions (CWE-266 and CWE-285) can give a remote adversary unauthenticated read or modification of sensitive PCI DSS status information.

Affected Systems

It affects Eleveo Call Recording Software version 9.7.0. No other product versions or components are listed as vulnerable, and the flaw is located in the /callrec/pci_dss_status.jsp component of this particular release.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a low overall exploitation probability, yet the exploit has been made publicly available, which represents a real threat.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch once it becomes available.
  • Restrict access to the /callrec/pci_dss_status.jsp endpoint by using firewall rules or web server ACLs to allow only trusted IP ranges.
  • Monitor web server and application logs for repeated or suspicious access attempts to the pci_dss_status.jsp page, and investigate any anomalous activity.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 18:30:00 +0000


Sun, 12 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software pci_dss_status.jsp improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T19:19:11.777Z

Reserved: 2026-07-11T09:33:19.930Z

Link: CVE-2026-15471

cve-icon Vulnrichment

Updated: 2026-07-13T19:17:53.727Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization