Description
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
Published: 2026-08-14
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use of a hard‑coded password, 'changeme', in the employee onboarding component allows an unauthenticated remote attacker to authenticate as any employee whose email address is known. The onboarding form does not provide a password field, and the employee save controller falls back to the literal password when no password is supplied. The flaw is a classic example of hard‑coded credentials, identified by CWE‑798, and results in complete impersonation of employees without any initial authentication.

Affected Systems

Roskus Prospero Flow CRM before version 5.15.9 is vulnerable. Any installation of the product without the 5.15.9 or later patch is affected. The issue is specific to the human resources component that handles employee onboarding.

Risk and Exploitability

The CVSS score of 9.3 marks this flaw as critical, and although no EPSS score is reported, the lack of a required authentication step and the availability of a simple default password make exploitation readily feasible. The vulnerability is not listed in CISA KEV, but organizations using the default onboarding flow can immediately impersonate employees. Theory suggests that the attacker can trigger the flaw by submitting a user registration request to the standard onboarding endpoint with only the email field.

Generated by OpenCVE AI on August 14, 2026 at 15:22 UTC.

Remediation

Vendor Solution

Upgrade to or use version 5.15.9 or higher, and then reset the password of every employee onboarded through the affected flow.


Vendor Workaround

Reset the password of every employee onboarded through the affected flow.


OpenCVE Recommended Actions

  • Upgrade Prospero Flow CRM to version 5.15.9 or later.
  • Reset the passwords of all employees who were onboarded through the affected employee onboarding flow.
  • Verify that the employee onboarding form no longer submits credentials and that the employee save controller no longer defaults to the hard‑coded password.

Generated by OpenCVE AI on August 14, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
Title Use of hard-coded credentials in Prospero Flow CRM employee onboarding
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-798
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Roskus Prospero Flow Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-14T14:36:44.645Z

Reserved: 2026-08-14T12:22:02.795Z

Link: CVE-2026-19871

cve-icon Vulnrichment

Updated: 2026-08-14T14:36:41.033Z

cve-icon NVD

Status : Received

Published: 2026-08-14T14:16:51.493

Modified: 2026-08-14T15:17:09.207

Link: CVE-2026-19871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T15:30:03Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials