Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to 5.3.2 or later; first tagged release with the fix is v5.5.3. Review the supplier table for altered company_id values and rotate exposed order-portal credentials and bank details.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body. | |
| Title | IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-639 CWE-862 |
|
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-24T13:01:26.201Z
Reserved: 2026-08-24T11:49:04.308Z
Link: CVE-2026-78365
Updated: 2026-08-24T12:59:40.821Z
Status : Received
Published: 2026-08-24T13:19:19.247
Modified: 2026-08-24T14:17:04.637
Link: CVE-2026-78365
No data.
OpenCVE Enrichment
Updated: 2026-08-24T17:30:06Z