CVE-2026-77759 | Roskus Prospero Flow CRM up to 5.3.5 Transaction API /api/transaction ID authorization
A vulnerability was found in Roskus Prospero Flow CRM up to 5.3.5. It has been rated as problematic. The impacted element is an unknown function of the file /api/transaction of the component Transaction API. This manipulation of the argument ID causes authorization bypass.
This vulnerability appears as CVE-2026-77759. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More