Junglewise Threat Intelligence

CVE-2026-15470: Eleveo Call Recording Software improper authorization in group.jsp

CVE-2026-15470 · Severity: medium · CVSS 4.3 · Published 2026-07-12

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software version 9.7.0 contains a security flaw that allows users with low-level access to bypass certain authorization checks. This could allow an attacker to view information or access group-related settings they are not permitted to see. The vulnerability is publicly known, and the manufacturer has not yet provided a response or a fix.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the /callrec/group.jsp file. The flaw allows a remote attacker with low-privileged credentials (PR:L) to perform unauthorized actions or access data due to incorrect privilege assignment. The attack vector is network-based and does not require user interaction. A public exploit has been disclosed, but as of the advisory date, the vendor has not responded to the disclosure or released a patch.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-12: disclosed: Public disclosure of the vulnerability and exploit
  • 2026-07-12: advisory: CVE-2026-15470 published via VulDB/NVD

References

Related threats