CVE-2026-47755: CWE-639: Authorization Bypass Through User-Controlled Key in itflow-org itflow
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
AI Analysis
Technical Summary
CVE-2026-47755 is an authorization bypass vulnerability in the ITFlow product by itflow-org. Before version 26.05, a low-privileged authenticated agent can retrieve sensitive information such as plaintext credentials and TOTP secrets belonging to other clients by directly requesting the credential edit modal with an arbitrary credential_id. The vulnerability arises because the endpoint does not enforce client scoping or object-level authorization checks prior to loading and decrypting the credential record. This allows unauthorized access to sensitive authentication data. The issue is resolved in version 26.05.
Potential Impact
An attacker with low-privileged authenticated access can obtain plaintext credentials and TOTP secrets of other clients, leading to potential compromise of client accounts and authentication mechanisms. The confidentiality of sensitive authentication data is directly impacted. There is no indication of impact to integrity or availability.
Mitigation Recommendations
Upgrade ITFlow to version 26.05 or later, where this authorization bypass vulnerability is fixed. Patch status is not explicitly stated but the vendor has fixed the issue in 26.05. Until upgrading, restrict access to trusted users only and monitor for suspicious access patterns involving credential_id parameters.
CVE-2026-47755: CWE-639: Authorization Bypass Through User-Controlled Key in itflow-org itflow
Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-47755 is an authorization bypass vulnerability in the ITFlow product by itflow-org. Before version 26.05, a low-privileged authenticated agent can retrieve sensitive information such as plaintext credentials and TOTP secrets belonging to other clients by directly requesting the credential edit modal with an arbitrary credential_id. The vulnerability arises because the endpoint does not enforce client scoping or object-level authorization checks prior to loading and decrypting the credential record. This allows unauthorized access to sensitive authentication data. The issue is resolved in version 26.05.
Potential Impact
An attacker with low-privileged authenticated access can obtain plaintext credentials and TOTP secrets of other clients, leading to potential compromise of client accounts and authentication mechanisms. The confidentiality of sensitive authentication data is directly impacted. There is no indication of impact to integrity or availability.
Mitigation Recommendations
Upgrade ITFlow to version 26.05 or later, where this authorization bypass vulnerability is fixed. Patch status is not explicitly stated but the vendor has fixed the issue in 26.05. Until upgrading, restrict access to trusted users only and monitor for suspicious access patterns involving credential_id parameters.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.505Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a624de29c2644c7f86dab8d
Added to database: 07/23/2026, 17:22:42 UTC
Last enriched: 07/23/2026, 17:37:55 UTC
Last updated: 07/23/2026, 22:56:05 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.