Junglewise Threat Intelligence

CVE-2026-15474: Eleveo Call Recording Software improper authorization in audio.jsp

CVE-2026-15474 · Severity: medium · CVSS 4.3 · Published 2026-07-12

Technologies: Eleveo Call Recording. Vendors: Eleveo.

Executive brief

A security flaw in Eleveo Call Recording Software could allow an authorized user to access audio recordings they are not permitted to view. By manipulating specific parameters in the software's web interface, a user could potentially listen to sensitive calls, leading to unauthorized data exposure. A public exploit for this vulnerability exists, and the vendor has not yet provided a fix.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in Eleveo Call Recording Software version 9.7.0 within the Call Recording Handler component. The flaw is located in the /callrec/audio.jsp file, where the application fails to properly validate user permissions against the 'callId' parameter. A remote, authenticated attacker can exploit this by modifying the 'callId' argument to access recordings belonging to other users or departments. A public proof-of-concept exploit has been released. As of the disclosure date, the vendor has not responded to reports or released a patch.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-07-12: advisory: Initial disclosure by VulDB/NVD
  • 2026-07-12: disclosed: Public exploit released

References

Related threats