🔐 CVE Alert

CVE-2026-19539

UNKNOWN 0.0

IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission.

CWE CWE-862
Vendor roskus
Product prospero flow crm
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for roskus prospero flow crm

Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Roskus / Prospero Flow CRM
0 < 5.4.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Roskus/prospero-flow-crm/commit/b2b6ffdace0972ab62d1f7e8cdab0ed213bfc4a9 github.com: https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-19539-idor-in-prospero-flow-crm-allows-cross-tenant-ticket-read-hijacking-and-deletion

Credits

Darío Rivas Quero Cristian Fernández Cornejo Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro