CVE-2026-59234 | Roskus Prospero Flow CRM up to 5.5.2 Calendar Event CalendarDeleteEventController.php delete ID authorization

SecurityVulns

A vulnerability was found in Roskus Prospero Flow CRM up to 5.5.2. It has been declared as problematic. Affected by this issue is the function delete of the file app/Http/Controllers/Calendar/CalendarDeleteEventController.php of the component Calendar Event Handler. Executing a manipulation of the argument ID can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-59234. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More