Unrated severityNVD Advisory· Published Jul 23, 2026· Updated Jul 28, 2026
ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal
CVE-2026-47755
Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary credential_id. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <26.05
Patches
Vulnerability mechanics
References
2- github.com/itflow-org/itflow/compare/v26.04...v26.05mitrex_refsource_MISC
- github.com/itflow-org/itflow/security/advisories/GHSA-987x-g5f9-2rpqmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.