Vulnerability Description
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
Related Weaknesses (CWE)
References
- https://github.com/Roskus/prospero-flow-crm/commit/59644f910b7d1aec7d1ac962b0354
- https://secur0.com/en/cna/cve-list/cve-2026-19870-idor-in-prospero-flow-crm-allo
FAQ
What is CVE-2026-19870?
CVE-2026-19870 is a documented vulnerability. Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and ...
How severe is CVE-2026-19870?
CVSS scoring is not yet available for CVE-2026-19870. Check NVD for updates.
Is there a patch for CVE-2026-19870?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.