Junglewise Threat Intelligence

CVE-2026-15471: Eleveo Call Recording Software improper authorization in pci_dss_status.jsp

CVE-2026-15471 · Severity: medium · CVSS 4.3 · Published 2026-07-12

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software, used by organizations to capture and manage communications, contains a security flaw in its PCI DSS status reporting component. An attacker with basic user access can bypass intended authorization checks to view information they should not be able to see. This could lead to the unauthorized disclosure of sensitive system status or compliance data, potentially impacting the organization's regulatory standing.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software 9.7.0 within the /callrec/pci_dss_status.jsp file. The flaw allows a remote attacker with low-privileged credentials to perform unauthorized manipulations that bypass intended access restrictions. Successful exploitation enables the attacker to access sensitive information related to PCI DSS status. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-12: advisory: NVD publication date
  • 2026-07-12: disclosed: Public exploit released via Google Drive PoC

References

Related threats