CVE-2026-59236

Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records inside another company's tenant via a spreadsheet whose company_id column points to the victim tenant, uploaded to POST /customer/import/excel/save, which maps company_id directly from the file and performs no check that it matches the authenticated user's company.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2026, 12:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 12:18

Updated : 2026-07-15 20:58


NVD link : CVE-2026-59236

Mitre link : CVE-2026-59236

CVE.ORG link : CVE-2026-59236


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key