CVE-2026-19539Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-11: 2Technical Details · 2026-08-11: 208-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19539 Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company… https://www.cve.org/CVERecord?id=CVE-2026-19539 ----- Traducción: CVE-2026-19539 Omi… http://infoflow.cloud`

    Post summary

    The text announces the new CVE‑2026‑19539 affecting Roskus Prospero Flow CRM before version 5.4.9, describing an authorization bypass via a user‑controlled key.

    0000034
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19539 Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company… https://www.cve.org/CVERecord?id=CVE-2026-19539

    Post summary

    The post references a CVE disclosure for an authorization bypass in Roskus Prospero Flow CRM, providing only the CVE identifier and a brief description without indicating exploitation, PoC, or remediation.

    00000835
    57.9K followersView on X

Explore more