Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body. | |
| Title | IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-639 CWE-862 |
|
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-24T13:01:26.201Z
Reserved: 2026-08-24T11:49:04.308Z
Link: CVE-2026-78365
Updated: 2026-08-24T12:59:40.821Z
Status : Received
Published: 2026-08-24T13:19:19.247
Modified: 2026-08-24T14:17:04.637
Link: CVE-2026-78365
No data.
OpenCVE Enrichment
Updated: 2026-08-24T17:30:06Z