Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77780— Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers

Quick assessment

Affected
Roskus Prospero Flow CRM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Roskus Prospero Flow CRM 4.9.1 至 5.14.0 版本中,交易保存端点(/transaction/save)存在通过用户可控键值绕过授权检查的漏洞。具备交易创建和会计创建权限的用户,可以通过向 POST /transaction/save 提交属于其他公司的 bank_account_id 或 bank_card_id,从而泄露该公司银行账户名称、银行名称以及银行卡后四位数字。由于该请求在持久化及渲染过程中未对公司所有权进行任何校验,导致攻击者能够越权访问非本公司敏感的银行账户信息

CVSS 5.3 · Medium EPSS 0.25% · P17

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
Roskus Prospero Flow CRM 4.9.1< 5.14.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77780

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers
Source: CVE Program / CVE List V5
Vulnerability Description
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Roskus Prospero Flow CRM 4.9.1 ~ 5.14.2 -

II. Public POCs for CVE-2026-77780

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77780

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77780 (2)

Other References for CVE-2026-77780 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77780

No comments yet


Leave a comment