CVE-2026-19870: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRM
CVE-2026-19870 is an authorization bypass vulnerability in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the system does not properly scope queries to the caller's company and validates employee identifiers only for global existence rather than company membership.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-19870) in Roskus Prospero Flow CRM prior to version 5.15.10 allows an authorization bypass via a user-controlled key in the payroll module. The flaw arises because the listing query for payroll data is not restricted to the user's company, and employee identifiers are validated only for global existence, not company membership. As a result, users with read payroll permission can access sensitive salary and banking information of employees from other companies, and users with create payroll permission can create payroll records for employees outside their company. The CVSS 4.0 score is 8.6, indicating high severity, with network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows unauthorized access to sensitive payroll information across company boundaries within the same CRM instance. Confidential salary and banking details can be viewed by users who should not have access, violating data confidentiality. Furthermore, unauthorized creation of payroll records for employees of other companies can compromise data integrity and potentially disrupt payroll processes.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided, users should monitor the vendor's communications for updates. Until a fix is available, restrict permissions for users with read or create payroll privileges to trusted personnel only and consider isolating company data instances if possible.
CVE-2026-19870: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRM
Description
CVE-2026-19870 is an authorization bypass vulnerability in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the system does not properly scope queries to the caller's company and validates employee identifiers only for global existence rather than company membership.
CVSS v4.0
Score 8.6high
Affected software
Roskus
Prospero Flow CRM
pkg:github/Prospero Flow CRMRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-19870) in Roskus Prospero Flow CRM prior to version 5.15.10 allows an authorization bypass via a user-controlled key in the payroll module. The flaw arises because the listing query for payroll data is not restricted to the user's company, and employee identifiers are validated only for global existence, not company membership. As a result, users with read payroll permission can access sensitive salary and banking information of employees from other companies, and users with create payroll permission can create payroll records for employees outside their company. The CVSS 4.0 score is 8.6, indicating high severity, with network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows unauthorized access to sensitive payroll information across company boundaries within the same CRM instance. Confidential salary and banking details can be viewed by users who should not have access, violating data confidentiality. Furthermore, unauthorized creation of payroll records for employees of other companies can compromise data integrity and potentially disrupt payroll processes.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided, users should monitor the vendor's communications for updates. Until a fix is available, restrict permissions for users with read or create payroll privileges to trusted personnel only and consider isolating company data instances if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Secur0
- Date Reserved
- 2026-08-14T11:53:44.193Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7f0995bf8831d53908b508
Added to database: 08/14/2026, 12:27:01 UTC
Last enriched: 08/21/2026, 14:03:55 UTC
Last updated: 09/29/2026, 01:47:40 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.