PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77759 Roskus CVE debrief

PatchSiren debrief for CVE-2026-77759 based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then. This vulnerability exists in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5, allowing an authenticated user to read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. Administrators and users should be aware of this vulnerability and take necessary precautions.

Vendor
Roskus
Product
Prospero Flow CRM
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Administrators and users of Roskus Prospero Flow CRM, especially those with low-privileged authenticated access, should be aware of this vulnerability and take necessary precautions to limit the scope of authenticated user permissions and implement proper authorization checks for transaction API. They should also monitor and restrict access to sensitive transaction data and update to a fixed version of Roskus Prospero Flow CRM if available. Additionally, security teams and vulnerability management teams should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Operators of affected platforms should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Those responsible for change management should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory managers should track exceptions, retest remediated assets, and close the item only after evidence is documented. Those involved in source tracking should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also review compensating controls for exposed systems while remediation is scheduled and verified. IT and security teams should work together to implement these measures and ensure the security of their systems and data. The CVE record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH. This information should be used to prioritize and coordinate response efforts effectively. Security teams should use this information to assess the potential impact on their systems and plan accordingly. They should also communicate with stakeholders and ensure that necessary measures are taken to mitigate the risk. A

Technical summary

The vulnerability exists in the transaction API of Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5. An authenticated user can read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. This issue has a CVSS score of 8.7 and is classified as HIGH. The vulnerability allows low-privileged authenticated users to potentially access sensitive transaction data.

Defensive priority

Authenticated users with low privileges may be able to read transactions of other companies.

Recommended defensive actions

  • Verify and limit the scope of authenticated user permissions
  • Implement proper authorization checks for transaction API
  • Monitor and restrict access to sensitive transaction data
  • Update to a fixed version of Roskus Prospero Flow CRM if available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE-2026-77759 record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then.