CVE-2026-15474 is a security flaw in Eleveo Call Recording Software 9.7.0. The vulnerability affects an unknown function of the file /callrec/audio.jsp in the Call Recording Handler component. The manipulation of the callId argument results in improper authorization, allowing remote attacks. The exploit has been publicly released. The vendor, Unknown Vendor, was contacted but did not respond.
CVE-2026-15471 is a low-severity vulnerability in Eleveo Call Recording Software 9.7.0, affecting the file /callrec/pci_dss_status.jsp and resulting in improper authorization. Remote exploitation is possible, and the exploit has been made public. Organizations using Eleveo Call Recording Software 9.7.0 should prioritize patching to prevent potential unauthorized access. The vulnerability has not been modi [truncated]
CVE-2026-15470 is an improper authorization vulnerability in Eleveo Call Recording Software 9.7.0, affecting the /callrec/group.jsp file. This issue allows for improper authorization and may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond. The vulnerability has a CVSS score of 2.1, indicating low s [truncated]
CVE-2026-15377 is an improper authorization vulnerability in Eleveo Call Recording Software 9.7.0, affecting an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization, allowing remote initiation of the attack. The exploit has been publicly disclosed and may be utilized. Organizations using Eleveo Call Recording Software 9.7.0 should assess their exposure an [truncated]
A vulnerability was found in Eleveo Call Recording Software 9.7.0, affecting an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability has a CVSS score of [truncated]
CVE-2026-15373 is an improper authorization vulnerability detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.do. Performing a manipulation of the argument role results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure b [truncated]