CVE-2026-59233
Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.
| CWE | CWE-639 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
0 < 5.2.1
References
github.com: https://github.com/Roskus/prospero-flow-crm/commit/86a7d6557bd111518a221f4575ad6e36087e19d3 github.com: https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-59233-missing-authorization-in-prospero-flow-crm-permission-endpoint
Credits
k1di3 Cristian Fernández Cornejo Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro