🔐 CVE Alert

CVE-2026-77759

UNKNOWN 0.0

IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.

CWE CWE-639
Vendor roskus
Product prospero flow crm
Published Aug 21, 2026
Last Updated Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for roskus prospero flow crm

Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Roskus / Prospero Flow CRM
5.0.0 < 5.3.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Roskus/prospero-flow-crm/commit/980c35ac00e419591a8adc2d1dbcc120ea62e273 github.com: https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-77759-idor-missing-authz-prospero-transaction-api

Credits

Marcos García (s3ntinl) Xoán M. Otero Jorge Cristian Fernández Cornejo Secur0 CNA Gustavo Novaro