Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting
creation permissions to disclose another company's bank account name, bank name and card
last four digits via a bank_account_id or bank_card_id belonging to that company in POST
/transaction/save, which is persisted and rendered without any company ownership check.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to 5.14.2 or later. No tagged release carries the fix; the newest tag v5.14.0 is affected. Rows already written are not corrected by the patch.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check. | |
| Title | Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-21T12:12:59.160Z
Reserved: 2026-08-21T11:30:36.990Z
Link: CVE-2026-77780
No data.
Status : Received
Published: 2026-08-21T13:18:20.423
Modified: 2026-08-21T13:18:20.423
Link: CVE-2026-77780
No data.
OpenCVE Enrichment
Updated: 2026-08-21T13:45:15Z