CVE-2026-15470: Eleveo Call Recording Software group.jsp improper authorization
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15470?
The severity of CVE-2026-15470 is medium with a score of 4.3.
How do I fix CVE-2026-15470?
To fix CVE-2026-15470, ensure that your Eleveo Call Recording Software is updated to the latest version provided by the vendor.
What type of vulnerability is CVE-2026-15470?
CVE-2026-15470 is an improper authorization vulnerability found in the group.jsp file of Eleveo Call Recording Software.
Can CVE-2026-15470 be exploited remotely?
Yes, CVE-2026-15470 can be exploited remotely.
What is the potential impact of CVE-2026-15470?
The potential impact of CVE-2026-15470 includes unauthorized access to functionalities within the Eleveo Call Recording Software.