🔐 CVE Alert

CVE-2026-59233

UNKNOWN 0.0

Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

CWE CWE-639
Vendor roskus
Product prospero flow crm
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for roskus prospero flow crm

Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Roskus / Prospero Flow CRM
0 < 5.2.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Roskus/prospero-flow-crm/commit/86a7d6557bd111518a221f4575ad6e36087e19d3 github.com: https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-59233-missing-authorization-in-prospero-flow-crm-permission-endpoint

Credits

k1di3 Cristian Fernández Cornejo Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro