Junglewise Threat Intelligence

CVE-2026-15374: Eleveo Call Recording Software improper authorization in Group Interface

CVE-2026-15374 · Severity: medium · CVSS 6.3 · Published 2026-07-10

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software, used by organizations to capture and manage telecommunications, contains a security flaw in its Group Interface. An attacker with basic user access can manipulate specific requests to gain unauthorized permissions or perform actions they should not be allowed to do. This could lead to unauthorized changes in system roles or access to sensitive call data, potentially compromising organizational compliance and privacy.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the Group Interface component. The flaw is located in the handling of requests to /callrec/roleAddAction.do, where insufficient validation allows for incorrect privilege assignment. A remote attacker with low-level authenticated access can manipulate these requests to escalate privileges or modify roles. While a proof-of-concept exploit has been published, the vendor has reportedly not responded to disclosure attempts, and no official patch is currently confirmed.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-10: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-07-10: advisory

References

Related threats