#CustomerImport
July 30, 2025 at 6:53 AM
🚨 EUVD-2026-44622
📊 6.9/10
🏢 Roskus

📝 Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44622

#cybersecurity #infosec #cve #euvd
July 15, 2026 at 1:01 PM
🚨 EUVD-2026-44622
📊 6.9/10
🏢 Roskus

📝 Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44622

#cybersecurity #infosec #cve #euvd
July 15, 2026 at 1:01 PM
CVE-2026-59236 - Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
CVE ID : CVE-2026-59236

Published : July 15, 2026, 11:09 a.m. | 23 minutes ago

Description : Authorization Bypass Through User-Controlled Key (CWE-639) in the Exc...
CVE-2026-59236 - Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records inside another company's tenant via a spreadsheet whose company_id column points to …
cvefeed.io
July 15, 2026 at 1:40 PM