CVE-2026-15472: Eleveo Call Recording Software composeEmailAction.do improper authorization
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15472?
CVE-2026-15472 has a medium severity rating of 4.3.
How do I fix CVE-2026-15472?
To fix CVE-2026-15472, ensure that you are using an updated version of Eleveo Call Recording Software that addresses this vulnerability.
What type of attack does CVE-2026-15472 allow?
CVE-2026-15472 allows for improper authorization attacks to be executed remotely.
In which software is CVE-2026-15472 found?
CVE-2026-15472 is found in Eleveo Call Recording Software version 9.7.0.
Is the exploit for CVE-2026-15472 publicly disclosed?
Yes, the exploit for CVE-2026-15472 has been publicly disclosed.