What is CVE-2026-19433?
CVE-2026-19433 is an Authorization Bypass Through User-Controlled Key vulnerability in the contact management component of Roskus Prospero Flow CRM. Before version 5.4.8, authenticated users from any company could blindly overwrite another company's contact data and download personal data as a vCard. Upgrading to version 5.4.8 or later is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-19433, Roskus Prospero Flow CRM-in kontakt idarəetmə komponentində aşkarlanmış Authorization Bypass Through User-Controlled Key zəifliyidir. 5.4.8 versiyasından əvvəlki versiyalarda, autentifikasiya olunmuş istənilən istifadəçi digər şirkətlərin kontakt məlumatlarını kor-koranə üzərinə yaza və vCard olaraq endirə bilər. Bu zəiflikdən qorunmaq üçün dərhal 5.4.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Roskus
FAQ2
Which product is affected by CVE-2026-19433?
This vulnerability affects the contact management component of Roskus Prospero Flow CRM.
How can I protect against CVE-2026-19433?
To mitigate this vulnerability, it is recommended to immediately upgrade Roskus Prospero Flow CRM to version 5.4.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.