CVE-2026-19433: Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier, because the save and export operations retrieve the record without constraining the query to the authenticated user's company.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Roskus Prospero Flow CRM contact management componentto a version that resolves this vulnerability.Fixed in 5.4.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19433?
CVE-2026-19433 has a risk rating of 65, indicating a moderate level of severity.
How do I fix CVE-2026-19433?
To fix CVE-2026-19433, upgrade to Roskus Prospero Flow CRM version 5.5.3 or later.
What does CVE-2026-19433 exploit?
CVE-2026-19433 exploits an authorization bypass in the contact management component of Roskus Prospero Flow CRM.
Who is affected by CVE-2026-19433?
Authenticated users of any company using Roskus Prospero Flow CRM versions before 5.4.8 are affected by CVE-2026-19433.
What can attackers do with CVE-2026-19433?
Attackers can overwrite contact data of another company and download personal data as a vCard due to CVE-2026-19433.