Executive brief
Eleveo Call Recording Software, used by organizations to manage and archive telecommunications, contains a security flaw in its user management component. An attacker with basic user access can manipulate account settings to gain unauthorized permissions or roles. This could allow a low-level user to escalate their privileges, potentially accessing sensitive recordings or administrative functions they should not be able to reach.
Technical details
An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the /callrec/userAddAction.do endpoint. The vulnerability is triggered by manipulating the 'role' argument during user creation or modification requests. A remote attacker with low-level authenticated access can exploit this to assign themselves or others higher privileges than intended. The exploit is currently public, and the vendor has reportedly not responded to disclosure attempts. The attack vector is network-based and does not require user interaction.
Affected products
- Eleveo Call Recording Software 9.7.0
Timeline
- 2026-07-10: advisory: Initial disclosure by VulDB and NVD
- 2026-07-10: disclosed: Public exploit released