๐Ÿ” CVE Alert

CVE-2026-61519

HIGH 8.8

Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.

CWE CWE-863
Vendor liberu software
Product liberu crm
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for liberu software liberu crm

Be the first to know when new high vulnerabilities affecting liberu software liberu crm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Liberu Software / Liberu CRM
0.9.1 < 10.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/liberusoftware/crm-laravel/issues/708 github.com: https://github.com/liberusoftware/crm-laravel/releases/tag/v10.0.0 github.com: https://github.com/liberusoftware/crm-laravel/commit/0846d067ae2e9c437e8555e54a4ec6517927b3d4 vulncheck.com: https://www.vulncheck.com/advisories/liberu-crm-broken-access-control-via-teampolicy-addteammember

Credits

rayyb0t