AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19870

HIGH · CVSS 8.6 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The payroll module in Roskus Prospero Flow CRM versions prior to 5.15.10 is vulnerable to an authorization bypass, allowing authenticated users with read payroll permissions to access sensitive salary and banking information of employees from any company within the system. Additionally, users with create payroll permissions can manipulate payroll records for employees belonging to other companies, due to insufficient scoping of queries and inadequate validation of employee identifiers. Organizations utilizing this CRM should prioritize patching to mitigate the risk of data exposure and unauthorized payroll manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19870
Severity
HIGH
CVSS
8.6
EPSS
N/A

Original NVD Description

Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership