What is CVE-2026-59233?
CVE-2026-59233 is a missing authorization vulnerability in the permission management component of Roskus Prospero Flow CRM before version 5.2.1. It allows any authenticated user to grant themselves or any other role full application permissions via a crafted POST request to the permission save endpoint. Upgrading to version 5.2.1 or later is strongly recommended to mitigate this issue.
Azərbaycanca: CVE-2026-59233 zəifliyi Roskus Prospero Flow CRM-in 5.2.1 versiyasından əvvəlki versiyalarında icazə idarəetmə komponentində aşkarlanıb. Bu, autentifikasiya olunmuş istənilən istifadəçiyə xüsusi POST sorğusu vasitəsilə öz daxil olduğu rol da daxil olmaqla istənilən rola bütün icazələri verməyə imkan verir. Təsirə məruz qalan sistemlərdə dərhal 5.2.1 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Roskus Prospero Flow CRM are vulnerable to CVE-2026-59233?
The CVE-2026-59233 vulnerability affects Roskus Prospero Flow CRM versions prior to 5.2.1.
What does the CVE-2026-59233 vulnerability allow an authenticated user to do?
This vulnerability allows any authenticated user to grant themselves or any other role full application permissions via a crafted POST request to the permission save endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.