Description
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus
Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting
creation permissions to disclose another company's bank account name, bank name and card
last four digits via a bank_account_id or bank_card_id belonging to that company in POST
/transaction/save, which is persisted and rendered without any company ownership check.
Published: 2026-08-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to 5.14.2 or later. No tagged release carries the fix; the newest tag v5.14.0 is affected. Rows already written are not corrected by the patch.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.
Title Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-639
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Roskus Prospero Flow Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-21T12:12:59.160Z

Reserved: 2026-08-21T11:30:36.990Z

Link: CVE-2026-77780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T13:18:20.423

Modified: 2026-08-21T13:18:20.423

Link: CVE-2026-77780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:45:15Z

Weaknesses