
🚨*CVE* CVE-2026-59233 Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their… https://www.cve.org/CVERecord?id=CVE-2026-59233 ----- Traducción: CVE-2026-59233 Fal… http://infoflow.cloud`
Post summary
CVE‑2026‑59233 exposes a missing‑authorization flaw in Roskus Prospero Flow CRM (before 5.2.1) that permits any authenticated user to grant themselves any role, with no mention of patch, PoC, or active exploitation.

