CVE-2026-77759
IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.
| CWE | CWE-639 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
5.0.0 < 5.3.6
References
Credits
Marcos García (s3ntinl) Xoán M. Otero Jorge Cristian Fernández Cornejo Secur0 CNA Gustavo Novaro