🔐 CVE Alert

CVE-2026-19871

UNKNOWN 0.0

Use of hard-coded credentials in Prospero Flow CRM employee onboarding

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.

CWE CWE-798
Vendor roskus
Product prospero flow crm
Published Aug 14, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for roskus prospero flow crm

Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Roskus / Prospero Flow CRM
0 < 5.15.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Roskus/prospero-flow-crm/commit/5cc01ed958db4ad0a026a8daa1c6a8bb98a43e66 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-19871-hardcoded-credentials-in-prospero-flow-crm-employee-onboarding

Credits

Adrián García López Darío Rivas Quero Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro