Executive brief
Eleveo Call Recording Software version 9.7.0 contains a security flaw that allows users with low-level access to bypass certain authorization checks. This could allow an attacker to view information or access group-related settings they are not permitted to see. The vulnerability is publicly known, and the manufacturer has not yet provided a response or a fix.
Technical details
An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the /callrec/group.jsp file. The flaw allows a remote attacker with low-privileged credentials (PR:L) to perform unauthorized actions or access data due to incorrect privilege assignment. The attack vector is network-based and does not require user interaction. A public exploit has been disclosed, but as of the advisory date, the vendor has not responded to the disclosure or released a patch.
Affected products
- Eleveo Call Recording Software 9.7.0
Timeline
- 2026-07-12: disclosed: Public disclosure of the vulnerability and exploit
- 2026-07-12: advisory: CVE-2026-15470 published via VulDB/NVD