Description
A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Eleveo Call Recording Software version 9.7.0 allows remote attackers to exploit the /callrec/restoreCallAction.do endpoint and bypass the application’s authorization checks. By manipulating requests to this endpoint, an attacker can restore or view call recordings without proper permission, exposing confidential audio data and compromising the privacy of users. This flaw corresponds to CWE-266 (Improper Privilege Assignment) and CWE-285 (Improper Authorization).

Affected Systems

Eleveo Call Recording Software, version 9.7.0, is affected by this authorization flaw. No other versions were identified as vulnerable in the available information.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while an EPSS score of less than 1% suggests that the likelihood of exploitation is currently low. Nonetheless, the attack is possible to be carried out remotely and the exploit code is publicly available. The vulnerability is not listed in CISA’s KEV catalog. The overall risk remains moderate, and organizations should treat it as a potential threat to confidentiality and integrity of recorded data.

Generated by OpenCVE AI on August 1, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade Eleveo Call Recording Software to a version that fixes the authorization issue.
  • Restrict remote access to the /callrec/restoreCallAction.do URL with firewall or network segmentation so that only authenticated users with the appropriate roles can reach it.
  • Review and enforce role‑based authorization checks within the Recorded Calls component to block unauthorized usage.

Generated by OpenCVE AI on August 1, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 18:30:00 +0000


Sun, 12 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-14T14:34:01.039Z

Reserved: 2026-07-11T09:33:25.486Z

Link: CVE-2026-15473

cve-icon Vulnrichment

Updated: 2026-07-14T14:33:55.097Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization