CVE-2026-19870
Last modified
CVE-2026-19870 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Roskus | Prospero Flow CRM | < 5.15.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19870?
How severe is CVE-2026-19870?
How do I fix CVE-2026-19870?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19859The JetFormBuilder WordPress plugin before 3.6.5.2 does not …6.5
- CVE-2026-1986The FloristPress for Woo – Customize your eCommerce store fo…6.1
- CVE-2026-19861The JetFormBuilder — Dynamic Blocks Form Builder WordPress p…4.7
- CVE-2026-19862The JetFormBuilder WordPress plugin before 3.6.5.2 does not …4.8
- CVE-2026-19869@neo4j/graphql from 5.2.0 until the patched versions fails t…7.6
- CVE-2026-1987The Scheduler Widget plugin for WordPress is vulnerable to I…5.4
- CVE-2026-19871Use of Hard-coded Credentials in the human resources compone…9.3
- CVE-2026-19872HTML::FormHandler versions before 0.410000 for Perl allow cr…6.1
- CVE-2026-19873HTML::FormFu versions through 2.08 for Perl allow resource e…7.5
- CVE-2026-19874A heap-based buffer overflow vulnerability exists in Konami'…9.1
- CVE-2026-19875IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote a…7.5
- CVE-2026-19879A flaw was found in Undertow, an HTTP server, within its HTT…5.3
Are you affected by CVE-2026-19870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
