PatchSiren cyber security CVE debrief
CVE-2026-77759 Roskus CVE debrief
PatchSiren debrief for CVE-2026-77759 based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then. This vulnerability exists in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5, allowing an authenticated user to read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. Administrators and users should be aware of this vulnerability and take necessary precautions.
- Vendor
- Roskus
- Product
- Prospero Flow CRM
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of Roskus Prospero Flow CRM, especially those with low-privileged authenticated access, should be aware of this vulnerability and take necessary precautions to limit the scope of authenticated user permissions and implement proper authorization checks for transaction API. They should also monitor and restrict access to sensitive transaction data and update to a fixed version of Roskus Prospero Flow CRM if available. Additionally, security teams and vulnerability management teams should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Operators of affected platforms should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Those responsible for change management should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory managers should track exceptions, retest remediated assets, and close the item only after evidence is documented. Those involved in source tracking should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also review compensating controls for exposed systems while remediation is scheduled and verified. IT and security teams should work together to implement these measures and ensure the security of their systems and data. The CVE record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH. This information should be used to prioritize and coordinate response efforts effectively. Security teams should use this information to assess the potential impact on their systems and plan accordingly. They should also communicate with stakeholders and ensure that necessary measures are taken to mitigate the risk. A
Technical summary
The vulnerability exists in the transaction API of Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5. An authenticated user can read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. This issue has a CVSS score of 8.7 and is classified as HIGH. The vulnerability allows low-privileged authenticated users to potentially access sensitive transaction data.
Defensive priority
Authenticated users with low privileges may be able to read transactions of other companies.
Recommended defensive actions
- Verify and limit the scope of authenticated user permissions
- Implement proper authorization checks for transaction API
- Monitor and restrict access to sensitive transaction data
- Update to a fixed version of Roskus Prospero Flow CRM if available
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE-2026-77759 record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH.
Official resources
-
CVE-2026-77759 CVE record
CVE.org
-
CVE-2026-77759 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
4daa8cea-433a-44bd-9456-53b127fc289a
-
Source reference
4daa8cea-433a-44bd-9456-53b127fc289a
-
Source reference
4daa8cea-433a-44bd-9456-53b127fc289a
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then.