PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19870 Roskus CVE debrief

PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T13:17:38.523Z and has not been modified since then. This CVE-2026-19870 record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM's payroll module before version 5.15.10. The vulnerability allows authenticated users with read payroll permission to view salary and banking details of employees from other companies and users with create payroll permission to create payroll records for other company's employees. This is due to the listing query not being scoped to the caller's company and the employee identifier being validated for global existence rather than company membership. Administrators and users of Roskus Prospero Flow CRM, especially those with access to payroll records or creation permissions, should be aware of this vulnerability and take necessary actions to protect their instances.

Vendor
Roskus
Product
Prospero Flow CRM
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-01
Advisory published
2026-08-14
Advisory updated
2026-09-01

Who should care

Administrators and users of Roskus Prospero Flow CRM, especially those with access to payroll records or creation permissions, should be aware of this vulnerability and take necessary actions to protect their instances.

Technical summary

The vulnerability exists in the payroll module of Roskus Prospero Flow CRM before version 5.15.10. An authorization bypass through user-controlled key allows authenticated users with read payroll permission to view salary and banking details of employees from other companies. Additionally, users with create payroll permission can create payroll records attributed to another company's employees. This issue arises because the listing query is not scoped to the caller's company, and the employee identifier is validated for global existence rather than company membership.

Defensive priority

Authenticated users with read payroll permission can view salary and banking details of employees from other companies, while users with create payroll permission can create payroll records for other company's employees due to improper scoping of listing queries and employee identifier validation.

Recommended defensive actions

  • Review and apply the vendor's patch to update Roskus Prospero Flow CRM to version 5.15.10 or later.
  • Restrict access to payroll records and creation permissions to authorized personnel only.
  • Monitor payroll records for unauthorized access or modifications.
  • Implement additional logging and auditing to detect potential exploitation attempts.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE-2026-19870 record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM's payroll module before version 5.15.10. The vulnerability allows authenticated users with read payroll permission to view salary and banking details of employees from other companies and users with create payroll permission to create payroll records for other company's employees. This is due to the listing query not being scoped to the caller's company and the employee identifier being validated for global existence rather than company membership.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19870 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19870

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19870 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19870

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Roskus/prospero-flow-crm/commit/59644f910b7d1aec7d1ac962b0354b3ec209977e

    4daa8cea-433a-44bd-9456-53b127fc289a

  • Source reference

    Unverified legacy reference

    URL: https://secur0.com/en/cna/cve-list/cve-2026-19870-idor-in-prospero-flow-crm-allows-cross-tenant-payroll-disclosure-and-creation

    4daa8cea-433a-44bd-9456-53b127fc289a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.