CVE-2026-101145: Eleveo Call Recording Software User Management userAddAction.do ldap injection
Published Sep 28, 2026
·Updated
A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
Eleveo Call Recording Software=9.7.0
Event History
Sep 28, 2026
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack is remote and requires low privileges. No user interaction is required.
2
How likely is exploitation in practice?
A public exploit is available and may be used. The reported affected version is 9.7.0.