What is CVE-2026-19871?
CVE-2026-19871 is a use of hard-coded credentials vulnerability in the human resources component of Roskus Prospero Flow CRM prior to version 5.15.9. This flaw allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow by only knowing their email address. Users should immediately upgrade to version 5.15.9 or later to mitigate the risk.
Azərbaycanca: CVE-2026-19871, Roskus Prospero Flow CRM proqramının 5.15.9 versiyasından əvvəlki insan resursları komponentində aşkarlanmış sərt kodlaşdırılmış etimadnamə zəifliyidir. Bu boşluq autentifikasiya olunmamış uzaq hücumçuya yalnız işçinin e-poçt ünvanını bilməklə sistemə həmin işçi kimi daxil olmağa imkan verir. İstifadəçilərə dərhal proqramı 5.15.9 və ya daha yuxarı versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
In which software was CVE-2026-19871 discovered, and what is the affected version?
This vulnerability was discovered in the human resources component of Roskus Prospero Flow CRM prior to version 5.15.9.
How can an attacker exploit CVE-2026-19871 to authenticate?
The attacker can remotely authenticate as any employee onboarded through the standard flow by only knowing their email address, without requiring any prior authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.