Impact
ITFlow allows a low‑privileged authenticated user to retrieve plaintext credentials and TOTP secrets for other clients by requesting a credential edit modal with an arbitrary credential_id. The endpoint fails to enforce client scoping or object‑level authorization before decrypting the credential record, enabling an attacker to read sensitive information belonging to a different tenant. This vulnerability is classified as CWE‑639 and CWE‑862.
Affected Systems
The product itflow by itflow‑org is affected. Versions prior to 26.05 are vulnerable; the issue was fixed in version 26.05. Users running v26.04 or older must update.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of <1% suggests a low exploit probability. The vulnerability is not listed in CISA KEV. Exploitation requires authentication but does not require high privileges; an attacker can craft HTTP requests with a valid credential_id to access other clients’ credentials.
OpenCVE Enrichment