SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77780

MEDIUM · CVSS 5.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows users with transaction and accounting creation permissions in Roskus Prospero Flow CRM versions 4.9.1 to 5.14.0 to bypass authorization controls, enabling them to access sensitive banking information of other companies through the transaction save endpoint. This could lead to unauthorized disclosure of bank account names, bank names, and the last four digits of bank cards. Organizations using affected versions should prioritize addressing this issue to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77780
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.