🔐 CVE Alert

CVE-2026-77780

UNKNOWN 0.0

Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.

CWE CWE-639
Vendor roskus
Product prospero flow crm
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for roskus prospero flow crm

Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Roskus / Prospero Flow CRM
4.9.1 < 5.14.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Roskus/prospero-flow-crm/commit/5fd1fe862bbdcbacf5d7e05c1c123981d8809674 github.com: https://github.com/Roskus/prospero-flow-crm/pull/261 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-77780-idor-unvalidated-bank-foreign-keys-prospero-transaction-save

Credits

Adrián García López Xoán M. Otero Jorge Darío Rivas Quero Secur0 CNA Gustavo Novaro