AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19871

CRITICAL · CVSS 9.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The human resources component in Roskus Prospero Flow CRM prior to version 5.15.9 is vulnerable due to hard-coded credentials, allowing unauthenticated remote attackers to gain access as any employee by simply knowing their email address. This critical vulnerability poses a significant risk of unauthorized access to sensitive employee information and systems. Organizations using this CRM should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19871
Severity
CRITICAL
CVSS
9.3
EPSS
N/A

Original NVD Description

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.