CVE-2026-19871
Use of hard-coded credentials in Prospero Flow CRM employee onboarding
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
| CWE | CWE-798 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Aug 14, 2026 |
| Last Updated | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
0 < 5.15.9
References
Credits
Adrián García López Darío Rivas Quero Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro