Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus
Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting
creation permissions to disclose another company's bank account name, bank name and card
last four digits via a bank_account_id or bank_card_id belonging to that company in POST
/transaction/save, which is persisted and rendered without any company ownership check.

Project Subscriptions

Vendors Products
Prospero Flow Crm Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to 5.14.2 or later. No tagged release carries the fix; the newest tag v5.14.0 is affected. Rows already written are not corrected by the patch.


Workaround

No workaround given by the vendor.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.
Title Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-639
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-21T16:12:40.967Z

Reserved: 2026-08-21T11:30:36.990Z

Link: CVE-2026-77780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T13:18:20.423

Modified: 2026-08-21T16:18:23.523

Link: CVE-2026-77780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:45:15Z

Weaknesses