PatchSiren

itflow-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM itflow-org CVE published 2026-07-23

CVE-2026-47755

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. CVE-2026-47755 is a vulnerability in ITFlow that allows low-privileged authenticated agents to retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary credential_id. The endpoint does not enforce client scoping or o [truncated]