PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77759 Roskus CVE debrief

PatchSiren debrief for CVE-2026-77759 based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then. This vulnerability exists in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5, allowing an authenticated user to read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. Administrators and users should be aware of this vulnerability and take necessary precautions.

Vendor
Roskus
Product
Prospero Flow CRM
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-01
Advisory published
2026-08-21
Advisory updated
2026-09-01

Who should care

Administrators and users of Roskus Prospero Flow CRM, especially those with low-privileged authenticated access, should be aware of this vulnerability and take necessary precautions to limit the scope of authenticated user permissions and implement proper authorization checks for transaction API. They should also monitor and restrict access to sensitive transaction data and update to a fixed version of Roskus Prospero Flow CRM if available. Additionally, security teams and vulnerability management teams should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Operators of affected platforms should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Those responsible for change management should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory managers should track exceptions, retest remediated assets, and close the item only after evidence is documented. Those involved in source tracking should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also review compensating controls for exposed systems while remediation is scheduled and verified. IT and security teams should work together to implement these measures and ensure the security of their systems and data. The CVE record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH. This information should be used to prioritize and coordinate response efforts effectively. Security teams should use this information to assess the potential impact on their systems and plan accordingly. They should also communicate with stakeholders and ensure that necessary measures are taken to mitigate the risk. A

Technical summary

The vulnerability exists in the transaction API of Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5. An authenticated user can read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API resolves the request without company scoping and without any permission check. This issue has a CVSS score of 8.7 and is classified as HIGH. The vulnerability allows low-privileged authenticated users to potentially access sensitive transaction data.

Defensive priority

Authenticated users with low privileges may be able to read transactions of other companies.

Recommended defensive actions

  • Verify and limit the scope of authenticated user permissions
  • Implement proper authorization checks for transaction API
  • Monitor and restrict access to sensitive transaction data
  • Update to a fixed version of Roskus Prospero Flow CRM if available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE-2026-77759 record indicates an authorization bypass vulnerability in Roskus Prospero Flow CRM 5.0.0 through 5.3.5. An authenticated user may read transactions of other companies via an incremented identifier in GET /api/transaction/{id}. The vulnerability has a CVSS score of 8.7 and is classified as HIGH.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77759 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77759

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77759 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77759

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Roskus/prospero-flow-crm/commit/980c35ac00e419591a8adc2d1dbcc120ea62e273

    4daa8cea-433a-44bd-9456-53b127fc289a

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3

    4daa8cea-433a-44bd-9456-53b127fc289a

  • Source reference

    Unverified legacy reference

    URL: https://secur0.com/en/cna/cve-list/cve-2026-77759-idor-missing-authz-prospero-transaction-api

    4daa8cea-433a-44bd-9456-53b127fc289a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.