CVE-2026-61519: Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liberu CRMto a version that resolves this vulnerability.Fixed in 10.0.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any user with a pending invitation to a Liberu CRM team can exploit it. The attacker does not need existing team membership or administrative privileges, but can use the pending invitation email match to gain permission to send further invitations.
What access can an attacker obtain?
The attacker can invite an attacker-controlled second account with the admin role. After that account accepts the invitation, it receives full admin-level create, read, update, and delete access to all data scoped to the affected team.
What does exploitation require?
Exploitation requires a pending team invitation and the ability to send a POST request to the team-invitations route. The request specifies the admin role for another account, bypassing the intended privilege-level validation.
Which versions are affected?
Liberu CRM versions 0.9.1 before 10.0.0 are affected. Version 10.0.0 is identified as the fixed release.