Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-59237 - IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders

CVE ID :CVE-2026-59237 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.

5.

Originally reported by CVE Recent
0 comments

0 comments

Posting as LucidFalcon150
0/1000

No comments yet. Be the first to start the discussion.