CVE-2026-59233: Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Roskus Prospero Flow CRMto a version that resolves this vulnerability.Fixed in 5.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59233?
CVE-2026-59233 has a risk rating of 76, indicating a high potential for impact.
How do I fix CVE-2026-59233?
To fix CVE-2026-59233, upgrade Roskus Prospero Flow CRM to version 5.2.1 or later.
What type of vulnerability is CVE-2026-59233?
CVE-2026-59233 is a missing authorization vulnerability that allows privilege escalation.
Who is affected by CVE-2026-59233?
Any authenticated user of Roskus Prospero Flow CRM versions prior to 5.2.1 can be affected by CVE-2026-59233.
What can attackers do in CVE-2026-59233?
Attackers can grant themselves or others any application permissions through a crafted POST request to the permission save endpoint.