NONE · 0

CVE-2026-77759

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the ...

Vulnerability Description

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-77759?

CVE-2026-77759 is a documented vulnerability. Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the ...

How severe is CVE-2026-77759?

CVSS scoring is not yet available for CVE-2026-77759. Check NVD for updates.

Is there a patch for CVE-2026-77759?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.