Description
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier, because the save and export operations retrieve the record without constraining the query to the authenticated user's company.
Published: 2026-08-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated user of any company within Prospero Flow CRM to overwrite contact data belonging to another company and to export that contact’s personal information as a vCard. Because the save and export operations use the contact’s numeric identifier without verifying that the requesting user’s company matches the owner of the record, an attacker can blindly modify and disclose confidential data. This constitutes a bypass of authorization controls, leading to potential privacy violations and corruption of contact records.

Affected Systems

All installations of Roskus Prospero Flow CRM versions earlier than 5.4.8 are affected. The flaw exists in the contact management component and applies to the contact save and vCard export endpoints.

Risk and Exploitability

The CVSS score is 8.6, indicating a high‑severity vulnerability. The EPSS score is not available, but the flaw is not listed in the CISA KEV catalog. An attacker only needs to be authenticated within the CRM; the exploitation path involves supplying a legitimate contact identifier that belongs to a different company. Because the system is multi‑tenant, any authenticated user can impact records belonging to other tenants, increasing the overall risk to all users on the platform.

Generated by OpenCVE AI on August 10, 2026 at 17:57 UTC.

Remediation

Vendor Solution

Upgrade to version 5.4.8 or higher.


OpenCVE Recommended Actions

  • Upgrade Prospero Flow CRM to version 5.4.8 or higher as provided by the vendor.
  • If an immediate upgrade is not possible, modify the contact save and vCard export endpoints to verify that the requester’s company matches the target contact’s company, thereby preventing cross‑company writes and reads.
  • Segregate the CRM traffic with network segmentation, monitor logs for unusual cross‑company access attempts, and block or alert on unauthorized data operations.

Generated by OpenCVE AI on August 10, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier, because the save and export operations retrieve the record without constraining the query to the authenticated user's company.
Title Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-639
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Roskus Prospero Flow Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-10T17:53:38.907Z

Reserved: 2026-08-10T12:41:19.273Z

Link: CVE-2026-19433

cve-icon Vulnrichment

Updated: 2026-08-10T17:53:33.558Z

cve-icon NVD

Status : Received

Published: 2026-08-10T15:17:43.330

Modified: 2026-08-10T18:17:43.030

Link: CVE-2026-19433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T04:15:02Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key