Junglewise Threat Intelligence

CVE-2026-15473: Eleveo Call Recording Software improper authorization in Recorded Calls Page

CVE-2026-15473 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

A security flaw has been identified in Eleveo Call Recording Software, which is used by organizations to capture and manage telecommunications. An unauthorized user could potentially perform actions they are not permitted to, such as restoring or manipulating recorded calls. This could lead to the unauthorized retrieval of sensitive audio data or disruption of compliance records.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software version 9.7.0. The flaw is located within the 'Recorded Calls Page' component, specifically affecting the processing of the '/callrec/restoreCallAction.do' endpoint. A remote attacker with low-level privileges can exploit this issue to bypass intended access controls. A public exploit is available, and the vendor has reportedly not responded to disclosure attempts. The vulnerability allows for unauthorized manipulation or restoration of recorded call data.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-12: advisory: NVD publication date

References

Related threats