Junglewise Threat Intelligence

CVE-2026-85405: Eleveo Call Recording Software cross-site scripting in roleAddAction

CVE-2026-85405 · Severity: low · CVSS 3.5 · Published 2026-09-04

Vendors: Eleveo.

Executive brief

Eleveo Call Recording Software is a business communications application used to record and manage call recordings. The software contains a cross-site scripting vulnerability in its role management functionality that could allow an attacker to inject malicious scripts and compromise user sessions or steal sensitive data.

Technical details

A cross-site scripting (XSS) vulnerability exists in Eleveo Call Recording Software 9.7.0 in the /callrec/roleAddAction.do endpoint, where the name/username argument is not properly sanitized. An attacker can manipulate this parameter to inject arbitrary JavaScript code that executes in the context of other users' browsers. The vulnerability is remotely exploitable without authentication requirements and can be used to steal session cookies, perform unauthorized actions, or capture user credentials. Proof-of-concept code has been publicly released.

Affected products

  • Eleveo Call Recording Software 9.7.0

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: advisory

References