CVE-2026-19870: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRM
An authorization bypass vulnerability exists in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the query listing is not properly scoped to the caller's company, and employee identifiers are validated only for global existence rather than company membership.
AI Analysis
Technical Summary
CVE-2026-19870 describes an authorization bypass vulnerability in Roskus Prospero Flow CRM's payroll module before version 5.15.10. The flaw allows authenticated users with certain payroll permissions to access or manipulate payroll data of employees belonging to other companies within the same instance. The root cause is that the listing query does not restrict results to the user's company, and employee identifiers are validated only for existence globally, not for membership within the user's company. This enables unauthorized viewing and creation of payroll records across company boundaries.
Potential Impact
Unauthorized disclosure of sensitive payroll information such as salary and banking details can occur. Additionally, unauthorized creation of payroll records attributed to employees of other companies is possible. This compromises confidentiality and integrity of payroll data across companies sharing the same CRM instance.
Mitigation Recommendations
No official patch or fix is currently confirmed or available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict payroll module permissions to trusted users only and monitor for suspicious activity related to payroll data access or creation.
CVE-2026-19870: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRM
Description
An authorization bypass vulnerability exists in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the query listing is not properly scoped to the caller's company, and employee identifiers are validated only for global existence rather than company membership.
CVSS v4.0
Score 8.6high
Affected software
pkg:github/roskus/prospero-flow-crmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-19870 describes an authorization bypass vulnerability in Roskus Prospero Flow CRM's payroll module before version 5.15.10. The flaw allows authenticated users with certain payroll permissions to access or manipulate payroll data of employees belonging to other companies within the same instance. The root cause is that the listing query does not restrict results to the user's company, and employee identifiers are validated only for existence globally, not for membership within the user's company. This enables unauthorized viewing and creation of payroll records across company boundaries.
Potential Impact
Unauthorized disclosure of sensitive payroll information such as salary and banking details can occur. Additionally, unauthorized creation of payroll records attributed to employees of other companies is possible. This compromises confidentiality and integrity of payroll data across companies sharing the same CRM instance.
Mitigation Recommendations
No official patch or fix is currently confirmed or available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict payroll module permissions to trusted users only and monitor for suspicious activity related to payroll data access or creation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fjcx-q8g6-9m7g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-19870"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7f43e9bf8831d5395d6114
Added to database: 08/14/2026, 16:35:53 UTC
Last enriched: 08/14/2026, 16:40:43 UTC
Last updated: 08/15/2026, 02:41:00 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.