No advisories yet.
Solution
Upgrade to or use version 5.15.9 or higher, and then reset the password of every employee onboarded through the affected flow.
Workaround
Reset the password of every employee onboarded through the affected flow.
Fri, 14 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field. | |
| Title | Use of hard-coded credentials in Prospero Flow CRM employee onboarding | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-14T14:36:44.645Z
Reserved: 2026-08-14T12:22:02.795Z
Link: CVE-2026-19871
No data.
Status : Received
Published: 2026-08-14T14:16:51.493
Modified: 2026-08-14T14:16:51.493
Link: CVE-2026-19871
No data.
OpenCVE Enrichment
No data.