CVE-2026-77780 | Roskus Prospero Flow CRM up to 5.14.1 Transaction Save Endpoint /transaction/save bank_account_id/bank_card_id authorization
A vulnerability was found in Roskus Prospero Flow CRM up to 5.14.1. It has been rated as problematic. Affected is an unknown function of the file /transaction/save of the component Transaction Save Endpoint. Performing a manipulation of the argument bank_account_id/bank_card_id results in authorization bypass.
This vulnerability is reported as CVE-2026-77780. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More