High severityNVD Advisory· Published Aug 21, 2026
CVE-2026-77759
CVE-2026-77759
Description
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 5.0.0 - 5.3.5
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.