What is CVE-2026-19870?
CVE-2026-19870 is an Authorization Bypass Through User-Controlled Key vulnerability in the payroll module of Roskus Prospero Flow CRM. It allows authenticated users with read payroll permission to view salary and banking details of employees from any company in the instance, affecting versions prior to 5.15.10, which should be updated immediately.
Azərbaycanca: CVE-2026-19870, Roskus Prospero Flow CRM-in əmək haqqı modulunda "Authorization Bypass Through User-Controlled Key" zəifliyidir. Bu, autentifikasiya olunmuş və yalnız oxuma icazəsi olan istifadəçiyə sistemdəki istənilən şirkətin işçilərinin maaş və bank məlumatlarını görməyə imkan verir. 5.15.10 versiyasından əvvəlki versiyalar təsirlənir, dərhal güncəlləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Roskus
FAQ2
Does exploiting CVE-2026-19870 require the attacker to be authenticated?
Yes, exploiting this Authorization Bypass vulnerability requires the attacker to have an authenticated account with at least read payroll permission in the system.
Which versions of Roskus Prospero Flow CRM are affected by CVE-2026-19870?
This vulnerability affects all versions of Roskus Prospero Flow CRM prior to version 5.15.10. Updating to this version immediately is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.