Executive brief
Eleveo Call Recording Software, used by organizations to capture and manage telecommunications, contains a security flaw in its email composition component. An attacker with basic user access could exploit this vulnerability to bypass authorization controls. This could lead to unauthorized access to sensitive information or the ability to perform actions beyond their intended permissions.
Technical details
An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software version 9.7.0 within the /callrec/composeEmailAction.do endpoint. The flaw allows a remote, authenticated attacker with low-level privileges to bypass intended access controls through manipulation of the request. Successful exploitation could lead to unauthorized information disclosure or privilege escalation. A public exploit has been disclosed, and the vendor has reportedly not responded to initial disclosure attempts.
Affected products
- Eleveo Call Recording Software 9.7.0
Timeline
- 2026-07-12: advisory: NVD publication date
- 2026-07-11: disclosed: Public disclosure of the exploit