CVE-2026-78365
IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.
| CWE | CWE-639 CWE-862 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
4.0.0 < 5.3.2
References
Credits
Antonio Rivera Poblete Xoán M. Otero Jorge Cristian Fernández Cornejo Secur0 CNA Gustavo Novaro