Executive brief
Eleveo Call Recording Software, used by organizations to capture and manage telecommunications, contains a security flaw in its reporting module. An attacker with basic user access can bypass intended restrictions to perform unauthorized actions within the statistics reporting function. This could lead to unauthorized access to call data or disruption of reporting services, potentially impacting compliance and operational oversight.
Technical details
An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software version 9.7.0. The flaw is located within the '/callrec/statisticReportAction.do' endpoint. A remote attacker with low-privileged authenticated access can exploit this vulnerability to bypass intended access controls. Successful exploitation allows the attacker to perform unauthorized operations within the statistics reporting module. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Eleveo Call Recording Software 9.7.0
Timeline
- 2026-07-10: advisory: Initial disclosure by VulDB and NVD