CVEFinder.io

CVE-2026-77759

πŸ”Ά medium
πŸ” Scan for this CVE
Summary

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.

CVSS Score
-
EPSS Score
0.3
Exploit Probability
Published Date
2026-08-21
First Seen: 2026-08-22
🎯 CISA SSVC Assessment Updated: Aug 21, 2026
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
YES
Can be exploited automatically
πŸ’₯ Technical Impact
Partial
Limited system impact
πŸ† Discovered By
Marcos GarcΓ­a (s3ntinl) XoΓ‘n M. Otero Jorge (analyst) Cristian FernΓ‘ndez Cornejo (analyst) Secur0 CNA (coordinator) Gustavo Novaro (remediation developer)
SSVC data provided by CISA
Last Modified 2026-08-21
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 0

No affected products information available

πŸ”— References 3