NONE · 0

CVE-2026-19871

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the s...

Vulnerability Description

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-19871?

CVE-2026-19871 is a documented vulnerability. Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the s...

How severe is CVE-2026-19871?

CVSS scoring is not yet available for CVE-2026-19871. Check NVD for updates.

Is there a patch for CVE-2026-19871?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.