Junglewise Threat Intelligence

CVE-2026-15377: Eleveo Call Recording Software improper authorization in sendlogfile

CVE-2026-15377 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software, used by organizations to capture and manage telecommunications, contains a security flaw in its log handling component. An attacker with basic user access could potentially access system log files that they should not be authorized to view. While this does not allow for full system takeover, it could lead to the exposure of sensitive diagnostic information or system metadata.

Technical details

A vulnerability classified as improper authorization (CWE-285) and incorrect privilege assignment (CWE-266) exists in Eleveo Call Recording Software version 9.7.0. The flaw is located within the '/callrec/sendlogfile' endpoint. A remote attacker with low-privileged credentials can exploit this vulnerability to bypass intended access controls and retrieve log files. The exploit has been publicly disclosed as a proof-of-concept. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch has been confirmed.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-10: advisory: Initial disclosure by VulDB and NVD
  • 2026-07-10: disclosed: Public exploit/PoC made available via Google Drive link

References

Related threats