CVE-2026-61519: Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()

Published Sep 29, 2026
·
Updated

Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.

Affected Software

1 affected component
Liberu CRM>=0.9.1<10.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Liberu CRM to a version that resolves this vulnerability.

    Fixed in 10.0.0

Event History

Sep 29, 2026
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any user with a pending invitation to a Liberu CRM team can exploit it. The attacker does not need existing team membership or administrative privileges, but can use the pending invitation email match to gain permission to send further invitations.

2

What access can an attacker obtain?

The attacker can invite an attacker-controlled second account with the admin role. After that account accepts the invitation, it receives full admin-level create, read, update, and delete access to all data scoped to the affected team.

3

What does exploitation require?

Exploitation requires a pending team invitation and the ability to send a POST request to the team-invitations route. The request specifies the admin role for another account, bypassing the intended privilege-level validation.

4

Which versions are affected?

Liberu CRM versions 0.9.1 before 10.0.0 are affected. Version 10.0.0 is identified as the fixed release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203