CVE-2026-47755: CWE-639: Authorization Bypass Through User-Controlled Key in itflow-org itflow
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
AI Analysis
Technical Summary
CVE-2026-47755 is an authorization bypass vulnerability in itflow (an IT documentation, ticketing, and accounting system) affecting versions before 26.05. A low-privileged authenticated agent can exploit this flaw by requesting the credential edit modal with an arbitrary credential_id, thereby accessing plaintext credentials and TOTP secrets belonging to other clients. The root cause is the lack of client scoping and object-level authorization checks before loading and decrypting credential records. The vulnerability is addressed in version 26.05.
Potential Impact
An attacker with low-level authenticated access can obtain sensitive plaintext credentials and TOTP secrets of other clients, potentially compromising client accounts or systems. The vulnerability impacts confidentiality but does not affect integrity or availability. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and high confidentiality impact.
Mitigation Recommendations
Upgrade to itflow version 26.05 or later, where this authorization bypass vulnerability is fixed. No other mitigation or workaround is indicated. Patch status is not explicitly stated but the vendor has fixed the issue in version 26.05.
CVE-2026-47755: CWE-639: Authorization Bypass Through User-Controlled Key in itflow-org itflow
Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-47755 is an authorization bypass vulnerability in itflow (an IT documentation, ticketing, and accounting system) affecting versions before 26.05. A low-privileged authenticated agent can exploit this flaw by requesting the credential edit modal with an arbitrary credential_id, thereby accessing plaintext credentials and TOTP secrets belonging to other clients. The root cause is the lack of client scoping and object-level authorization checks before loading and decrypting credential records. The vulnerability is addressed in version 26.05.
Potential Impact
An attacker with low-level authenticated access can obtain sensitive plaintext credentials and TOTP secrets of other clients, potentially compromising client accounts or systems. The vulnerability impacts confidentiality but does not affect integrity or availability. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and high confidentiality impact.
Mitigation Recommendations
Upgrade to itflow version 26.05 or later, where this authorization bypass vulnerability is fixed. No other mitigation or workaround is indicated. Patch status is not explicitly stated but the vendor has fixed the issue in version 26.05.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.505Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a624de29c2644c7f86dab8d
Added to database: 07/23/2026, 17:22:42 UTC
Last enriched: 07/30/2026, 22:12:07 UTC
Last updated: 09/04/2026, 22:52:12 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.