Junglewise Threat Intelligence

CVE-2026-59233: Roskus Prospero Flow CRM missing authorization in permission management

CVE-2026-59233 · Severity: info · CVSS 8.8 · Published 2026-08-10

Technologies: Roskus Prospero Flow CRM. Vendors: Roskus.

Executive brief

Roskus Prospero Flow CRM is a customer relationship management (CRM) platform used to manage business operations and customer interactions. A flaw in its permission management system allows any authenticated user to modify role permissions and grant themselves or others administrative access, effectively bypassing all access controls and enabling full platform compromise.

Technical details

The vulnerability is a missing authorization check in the POST /permission endpoint's permission save functionality. Any authenticated user can craft a request to reassign permissions to any role without authorization validation, enabling privilege escalation from a low-privileged user (e.g., Seller) to SuperAdmin. The vulnerable component fails to validate that the requesting user has the authority to modify permissions before synchronizing submitted permissions to the target role. An attacker with valid application credentials can grant themselves or others permissions such as user deletion, company deletion, and other administrative actions. The fix, deployed in version 5.2.1, adds SuperAdmin authorization checks and validates all permission names and role IDs before processing.

Affected products

  • Roskus Prospero Flow CRM before 5.2.1

Timeline

  • 2026-08-10: disclosed
  • 2026: patched: Fixed in version 5.2.1

References

Related threats