{"api_version":"1","generated_at":"2026-08-22T02:57:03+00:00","cve":"CVE-2026-77759","urls":{"html":"https://cve.report/CVE-2026-77759","api":"https://cve.report/api/cve/CVE-2026-77759.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77759","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77759"},"summary":{"title":"IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records","description":"Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero\nFlow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other\ncompanies on the same instance via an incremented identifier in GET /api/transaction/{id},\nwhich is resolved without company scoping and without any permission check.","state":"PUBLISHED","assigner":"Secur0","published_at":"2026-08-21 12:16:36","updated_at":"2026-08-21 12:16:36"},"problem_types":["CWE-639","CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key"],"metrics":[{"version":"4.0","source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3","name":"https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3","refsource":"4daa8cea-433a-44bd-9456-53b127fc289a","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-77759-idor-missing-authz-prospero-transaction-api","name":"https://secur0.com/en/cna/cve-list/cve-2026-77759-idor-missing-authz-prospero-transaction-api","refsource":"4daa8cea-433a-44bd-9456-53b127fc289a","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/Roskus/prospero-flow-crm/commit/980c35ac00e419591a8adc2d1dbcc120ea62e273","name":"https://github.com/Roskus/prospero-flow-crm/commit/980c35ac00e419591a8adc2d1dbcc120ea62e273","refsource":"4daa8cea-433a-44bd-9456-53b127fc289a","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77759","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77759","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Roskus","product":"Prospero Flow CRM","version":"affected 5.0.0 5.3.6 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to 5.3.6 or later. The fix was not tagged; the first tagged release carrying it is\nv5.5.3.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Marcos García (s3ntinl)","lang":"en"},{"source":"CNA","value":"Xoán M. Otero Jorge","lang":"en"},{"source":"CNA","value":"Cristian Fernández Cornejo","lang":"en"},{"source":"CNA","value":"Secur0 CNA","lang":"en"},{"source":"CNA","value":"Gustavo Novaro","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-77759","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-21T11:52:40.208082Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-21T11:53:17.782Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["Transaction API"],"product":"Prospero Flow CRM","programFiles":["app/Http/Controllers/Api/Transaction/TransactionReadController.php","routes/api.php"],"repo":"https://github.com/Roskus/prospero-flow-crm","vendor":"Roskus","versions":[{"lessThan":"5.3.6","status":"affected","version":"5.0.0","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*","versionEndExcluding":"5.3.6","versionStartIncluding":"5.0.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Marcos García (s3ntinl)"},{"lang":"en","type":"analyst","value":"Xoán M. Otero Jorge"},{"lang":"en","type":"analyst","value":"Cristian Fernández Cornejo"},{"lang":"en","type":"coordinator","value":"Secur0 CNA"},{"lang":"en","type":"remediation developer","value":"Gustavo Novaro"}],"datePublic":"2026-08-21T11:21:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero\nFlow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other\ncompanies on the same instance via an incremented identifier in GET /api/transaction/{id},\nwhich is resolved without company scoping and without any permission check."}],"value":"Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero\nFlow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other\ncompanies on the same instance via an incremented identifier in GET /api/transaction/{id},\nwhich is resolved without company scoping and without any permission check."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-21T11:29:43.550Z","orgId":"4daa8cea-433a-44bd-9456-53b127fc289a","shortName":"Secur0"},"references":[{"tags":["patch"],"url":"https://github.com/Roskus/prospero-flow-crm/commit/980c35ac00e419591a8adc2d1dbcc120ea62e273"},{"tags":["release-notes"],"url":"https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3"},{"tags":["technical-description","third-party-advisory"],"url":"https://secur0.com/en/cna/cve-list/cve-2026-77759-idor-missing-authz-prospero-transaction-api"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade to 5.3.6 or later. The fix was not tagged; the first tagged release carrying it is\n<code>v5.5.3</code>."}],"value":"Upgrade to 5.3.6 or later. The fix was not tagged; the first tagged release carrying it is\nv5.5.3."}],"source":{"discovery":"EXTERNAL"},"tags":["x_open-source"],"title":"IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"4daa8cea-433a-44bd-9456-53b127fc289a","assignerShortName":"Secur0","cveId":"CVE-2026-77759","datePublished":"2026-08-21T11:29:43.550Z","dateReserved":"2026-08-21T10:08:00.647Z","dateUpdated":"2026-08-21T11:53:17.782Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-21 12:16:36","lastModifiedDate":"2026-08-21 12:16:36","problem_types":["CWE-639","CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key"],"metrics":{"cvssMetricV40":[{"source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-21T11:52:40.208082Z","id":"CVE-2026-77759","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77759","Ordinal":"1","Title":"IDOR and missing authorization in the Prospero Flow CRM transact","CVE":"CVE-2026-77759","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77759","Ordinal":"1","NoteData":"Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero\nFlow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other\ncompanies on the same instance via an incremented identifier in GET /api/transaction/{id},\nwhich is resolved without company scoping and without any permission check.","Type":"Description","Title":"IDOR and missing authorization in the Prospero Flow CRM transact"}]}}}