CVE-2026-19870: IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Roskus Prospero Flow CRMto a version that resolves this vulnerability.Fixed in 5.15.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19870?
CVE-2026-19870 has a risk score of 75, indicating a high severity level.
How do I fix CVE-2026-19870?
To fix CVE-2026-19870, upgrade Roskus Prospero Flow CRM to version 5.15.10 or later.
What causes CVE-2026-19870?
CVE-2026-19870 is caused by an authorization bypass in the payroll module that allows users to access data across tenants.
Who is affected by CVE-2026-19870?
Authenticated users with payroll read permissions in Roskus Prospero Flow CRM prior to version 5.15.10 are affected by CVE-2026-19870.
What types of data can be exposed due to CVE-2026-19870?
CVE-2026-19870 can lead to unauthorized disclosure of salary and banking details of employees from other companies.