Junglewise Threat Intelligence

CVE-2026-15472: Eleveo Call Recording Software improper authorization in composeEmailAction.do

CVE-2026-15472 · Severity: medium · CVSS 4.3 · Published 2026-07-12

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software, used by organizations to capture and manage telecommunications, contains a security flaw in its email composition component. An attacker with basic user access could exploit this vulnerability to bypass authorization controls. This could lead to unauthorized access to sensitive information or the ability to perform actions beyond their intended permissions.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software version 9.7.0 within the /callrec/composeEmailAction.do endpoint. The flaw allows a remote, authenticated attacker with low-level privileges to bypass intended access controls through manipulation of the request. Successful exploitation could lead to unauthorized information disclosure or privilege escalation. A public exploit has been disclosed, and the vendor has reportedly not responded to initial disclosure attempts.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-12: advisory: NVD publication date
  • 2026-07-11: disclosed: Public disclosure of the exploit

References

Related threats