CVE-2026-77759

Source
https://cve.org/CVERecord?id=CVE-2026-77759
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77759.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77759
Published
2026-08-21T11:29:43.550Z
Modified
2026-09-03T03:30:42.250374653Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records
Details

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77759.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.3.6"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.3.6"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.3.5"
                }
            ]
        }
    ],
    "cna_assigner": "Secur0",
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/roskus/prospero-flow-crm

Affected ranges

Type
GIT
Repo
https://github.com/roskus/prospero-flow-crm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.0.0
v2.*
v2.0.1
v4.*
v4.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77759.json"