CVE-2026-19871 PUBLISHED

Use of hard-coded credentials in Prospero Flow CRM employee onboarding

Assigner: Secur0
Reserved: 14.08.2026 Published: 14.08.2026 Updated: 14.08.2026

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Roskus
Product Prospero Flow CRM
Versions Default: unaffected
  • affected from 0 to 5.15.9 (excl.)

Workarounds

Reset the password of every employee onboarded through the affected flow.

Solutions

Upgrade to or use version 5.15.9 or higher, and then reset the password of every employee onboarded through the affected flow.

Credits

  • Adrián García López finder
  • Darío Rivas Quero analyst
  • Xoán M. Otero Jorge analyst
  • Secur0 CNA coordinator
  • Gustavo Novaro remediation developer

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE

Impacts

  • CAPEC-70 Try Common or Default Usernames and Passwords