Description
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to manipulate the /callrec/composeEmailAction.do endpoint in Eleveo Call Recording Software version 9.7.0, resulting in improper authorization. This flaw is listed as CWE-266 and CWE-285, indicating failures in enforcing authentication and authorization checks. An attacker who can send crafted requests to this endpoint can invoke actions normally restricted to privileged users, potentially accessing or sending recordings via the email composition feature.

Affected Systems

Eleveo Call Recording Software version 9.7.0 is affected. No other versions have been explicitly reported as vulnerable. The vendor's product is listed as Eleveo:Call Recording Software.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as moderate and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. Because the flaw can be triggered remotely through HTTP requests to the composeEmailAction.do endpoint, it remains publicly exploitable. As it is not listed in the CISA KEV catalog, there have been no public reports of widespread usage, but the lack of a vendor fix means it continues to pose a risk to installations that allow the endpoint to be reached from untrusted networks.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network or application access to the composeEmailAction.do endpoint so that only authorized accounts can invoke it.
  • Disable or remove the composeEmailAction.do functionality if it is not required for business operations.
  • Implement network segmentation or firewall rules to limit exposure of the affected endpoint to trusted hosts.
  • When an official patch is released by the vendor, upgrade Eleveo Call Recording Software to the fixed version.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 18:30:00 +0000


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software composeEmailAction.do improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T18:22:36.516Z

Reserved: 2026-07-11T09:33:22.603Z

Link: CVE-2026-15472

cve-icon Vulnrichment

Updated: 2026-07-13T16:58:08.542Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization