Junglewise Threat Intelligence

CVE-2026-15375: Eleveo Call Recording Software improper authorization in LDAP User Interface

CVE-2026-15375 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software, used by organizations to manage and store telecommunications data, contains a security flaw in its LDAP user interface. An attacker with basic user access can exploit this vulnerability to bypass intended authorization controls. This could allow unauthorized individuals to view sensitive information they should not have access to, potentially compromising privacy and compliance standards.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the LDAP User Interface component. The flaw is located in the /callrec/users_ldap.jsp file, where insufficient permission checks allow a remote authenticated user with low privileges to perform actions or access data beyond their intended scope. The attack vector is network-based and requires basic user authentication. While a public exploit has been disclosed, the vendor has reportedly not responded to the disclosure, and no official patch is currently confirmed.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-10: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-07-10: advisory: CVE-2026-15375 published.

References

Related threats